Tag: Microsoft Entra SaaS Apps

nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery
News

nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery

Microsoft's Entra ID has a known security flaw that might let malicious actors to take over accounts in vulnerable software-as-a-service (SaaS) apps, according to new research. In an examination of 104 SaaS services, identity security firm Semperis discovered that nine of them were susceptible to Entra ID cross-tenant nOAuth exploitation. nOAuth is a flaw in the way SaaS apps use OpenID Connect (OIDC), an authentication layer that is built on top of OAuth to confirm a user's identity. Descope first revealed this flaw in June 2023. In essence, the authentication implementation vulnerability enables a malicious actor to use the "Log in with Microsoft" function of the app to take over a victim's account by changing the mail attribute in the Entra ID account to that of the victim rea...