Skip to content
June 23, 2026
☍ CyberNoz
  • Home
Home›Mix›CSRF protection on OIDC login is broken
Mix

CSRF protection on OIDC login is broken

Cybernoz
April 8, 2023 1 min read
Share X / Twitter LinkedIn Reddit WhatsApp Email



Nextcloud disclosed a bug submitted by mikaelgundersen: https://hackerone.com/reports/1878381



Source link

Share X / Twitter LinkedIn Reddit WhatsApp Email
« Previous
Top 3 Most Dangerous Lines of Code
Next »
Unveiling the Wild World of Bug Bounties

Related Articles

All Mix →
Exploring PathLib A path manipulation library for Net scaled Mix

Exploring PathLib – A path manipulation library for .Net

Table of Contents Why a library for paths? What is PathLib? Factories PurePathFactory PathFactory Serialization PathLib is available on NuGet and its source can be…

April 1, 2023 Cybernoz 5 min read
I am the greatest New HackerOne Quarterly Leaderboards Mix

The World’s Largest Live Hacking Event

h1-2010 Live Hacking Video Recap Thu, 12/10/2020 – 18:43 Sam Spielman How can we make this one different?  For organizations that operate in the digital…

September 8, 2023 Cybernoz 5 min read
Tapping Hackers for Continuous Security Mix

Expanding Reputation: Introducing Signal and Impact

Table of Contents Why We're Improving Reputation New Dimensions: Signal and Impact Examples Conclusions Edited on 4/8/2016 to reflect the latest Signal and Impact implementations.…

June 1, 2023 Cybernoz 2 min read
That Was Then, This Is Now Mix

That Was Then, This Is Now

[ From a Forwarded Email ] School, 1967 vs. 2007 Scenario: Jack goes quail hunting before school, pulls into school parking lot with shotgun in…

April 8, 2025 Cybernoz 3 min read
Study: SMTP | Daniel Miessler Mix

Study: SMTP | Daniel Miessler

SMTPRFC 821 SMTP is the main protocol used for sending mail on the Internet. Understanding it to at least a moderate degree is a must.…

April 1, 2025 Cybernoz 3 min read
Exploiting JWT vulnerabilities to achieve RCE Mix

Exploiting JWT vulnerabilities to achieve RCE

At Intigriti, we host monthly web-based Capture The Flag (CTF) challenges as a way to engage with the security research community. This month, we’ve decided…

November 25, 2025 Cybernoz 8 min read

Latest Posts

  • Court rules SAVE database illegal, orders it dismantled
  • Klue breach exposed Salesforce CRM data through stolen OAuth tokens
  • Following user outcry, AMD reinstates memory encryption in consumer CPUs
  • Bringing Security Visibility to Vercel with Wiz
  • Guarding AI memory | Microsoft Security Blog
  • Agbi
  • ArsTechnica
  • AttackDefense
  • Australiancybersecuritymagazine
  • Bankinfosecurity
  • Bleeping Computer
  • CISOOnline
  • CloudSecurity
  • ComputerWeekly
  • Crowdstrike
  • Cyber Security Ventures
  • CyberDefenseMagazine
  • CyberNews
  • Cyberscoop
  • CyberSecurity-Insiders
  • CyberSecurityDive
  • CyberSecurityNews
  • CyberWire
  • DarkReading
  • ExploitOne
  • GBHackers
  • Genel
  • HackerCombat
  • HackRead
  • HelpnetSecurity
  • IndustrialCyber
  • InfoSecurity
  • ITnews
  • ITSecurityGuru
  • Krebson
  • MalwareBytes
  • Mix
  • OTSecurity
  • PortSwigger
  • Rapid7
  • SCMP
  • securelist
  • Securityaffairs
  • SecurityWeek
  • techcrunch
  • TheCyberExpress
  • TheHackerNews
  • ThreatIntelligence-IncidentResponse
  • Tldrsec
  • Unit42
  • VendorResearch
  • welivesecurity
  • Wired
  • Zerosalarium
☍ CyberNoz

Cybersecurity News

  • Agbi
  • ArsTechnica
  • AttackDefense
  • Australiancybersecuritymagazine
  • Bankinfosecurity
  • Bleeping Computer
  • CISOOnline
  • CloudSecurity
  • ComputerWeekly
  • Crowdstrike
  • Cyber Security Ventures
  • CyberDefenseMagazine
  • CyberNews
  • Cyberscoop
  • CyberSecurity-Insiders
  • CyberSecurityDive
  • CyberSecurityNews
  • CyberWire
  • DarkReading
  • ExploitOne
  • GBHackers
  • Genel
  • HackerCombat
  • HackRead
  • HelpnetSecurity
  • IndustrialCyber
  • InfoSecurity
  • ITnews
  • ITSecurityGuru
  • Krebson
  • MalwareBytes
  • Mix
  • OTSecurity
  • PortSwigger
  • Rapid7
  • SCMP
  • securelist
  • Securityaffairs
  • SecurityWeek
  • techcrunch
  • TheCyberExpress
  • TheHackerNews
  • ThreatIntelligence-IncidentResponse
  • Tldrsec
  • Unit42
  • VendorResearch
  • welivesecurity
  • Wired
  • Zerosalarium
Archive
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
© 2026 Cybernoz. All rights reserved.