Last week a major flaw was reported in implementations of widely used authentication and authorization standards, OAUTH and OpenID. Many consumer and enterprise SaaS apps let users authenticate using these standards. This vulnerability, called “Covert Redirect,” enables attackers to insert themselves into the URL redirect path during the authentication process.
This flaw, though recently reported, isn’t new. Security researchers have noted similar problems in the way OAU