Skip to content

Latest commit

 

History

History
23 lines (22 loc) · 794 Bytes

ALEPH-2014011.md

File metadata and controls

23 lines (22 loc) · 794 Bytes
layout credit timeline alephid date title severity product mitigation references
vuln
peles
roeeh
type date
add
2017-03-01
type date
release
2014-12-03
ALEPH-2014011
2014-12-03
VASCO MyDigipass OAuth Unverified Email Social Login Bypass
high
VASCO MyDigipass
VASCO MyDigipass is now patched.
src url
paper: SpoofedMe - Intruding Account using Social Plogin Providers

VASCO MyDigipass supplied the account’s email addresses as part of the social login authentication process even when the user’s ownership of this email address had not been positively verified. This allowed for a social login attack as detailed in the paper.