Home / Companies / Clerk / Blog / Post Details
Content Deep Dive

Mitigating OAuth’s recently discovered Open Response Type vulnerability

Blog post from Clerk

Post Details
Company
Date Published
Author
Colin Sidoti
Word Count
1,370
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

Security researchers at Salt uncovered an OAuth vulnerability that can be combined with any XSS vulnerability to facilitate account takeovers. Clerk, a company involved in OAuth implementations, swiftly addressed the issue upon discovery, noting that their default configuration already protected over 99.7% of their customers. They released an update to safeguard the remaining users. The vulnerability, termed "Open Response Type," involves manipulating OAuth's response_type parameter to extract unused secret codes from URLs, potentially bypassing HttpOnly protections even after XSS vulnerabilities are patched. Clerk mitigated this by processing OAuth codes on separate origins to prevent XSS exploits and by removing unexpected URL fragments to stop malicious actors from gaining unauthorized access.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.