Quantcast
Channel: Security – OpenID
Viewing all articles
Browse latest Browse all 7

Covert Redirect

$
0
0

“Covert Redirect”, publicized in May, 2014, is an instance of attackers using open redirectors – a well-known threat, with well-known means of prevention. The OpenID Connect protocol mandates strict measures that preclude open redirectors to prevent this vulnerability.

Please see Section 4.2.4 of RFC 6819 (http://tools.ietf.org/html/rfc6819#section-4.2.4) for more information on open redirector threats and their prevention.


Viewing all articles
Browse latest Browse all 7

Trending Articles