WhisperX tag archive

#OAuth2

This page collects WhisperX intelligence signals tagged #OAuth2. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-03 15:27:00 · GitHub Issues

1. Athena M2M OAuth2 Client Secret Exposed in Next.js Logs — Critical P0 Vulnerability

A critical security vulnerability has been identified within the Athena platform's machine-to-machine OAuth2 client registration system. The flaw exposes plaintext client secrets in server logs, creating a high-risk data leak. The issue is classified as Priority P0 (Critical) and maps directly to the OWASP A02:2021 cat...

The Lab · 2026-04-03 15:27:02 · GitHub Issues

2. Athena M2M API Exposed: Admin Bypass Allows Arbitrary, Potentially Admin-Level Scope Assignment

A critical access control vulnerability has been identified in the Athena platform's machine-to-machine (M2M) client registration system. The flaw allows any authenticated administrator to bypass the intended security controls and assign arbitrary, potentially dangerous OAuth2 scopes to new M2M clients. This server-sid...

The Lab · 2026-05-07 18:31:40 · GitHub Issues

3. Ory Hydra consent flow vulnerability: arbitrary logo injection enables cookie exfiltration and clickjacking

A security research disclosure identifies multiple hardening gaps in Ory Hydra's consent and device authorization flows that, if exploited, could expose user credentials and enable UI-based attacks. The most actionable issue involves the consent page template at `consent.html`, which renders a logo specified by the OA...