Microsoft Account’s OAuth tokens leaking via open redirect in Harvest App::Reported an OAuth token leak via open redirect in Harvest.

  • @ShunkW
    link
    211 months ago

    3 years from report to patch is fucking abysmal.

  • @[email protected]
    link
    fedilink
    111 months ago

    Wow, I thought this was further reporting on their leaks earlier this year. Nono, it’s another vulnerability. Microsoft really living up to their reputation…

    • jlar
      link
      211 months ago

      From the post: "I apologise for the poor and confusing title used before. I have updated the title but I cannot change it everywhere else. Just to clarify This is not a vulnerability in Microsoft.’

      • jlar
        link
        211 months ago

        Not to defend M$ lol. Just in this case it was Harvest with the vuln.