Remove .well-known openid-configuration
article thumbnail

Top Trending CVEs of November 2023

NopSec

well-known/openid-configuration” and “/oauth/rp/.well-known/openid-configuration”. well-known/openid-configuration”. These functions are responsible for returning an OpenID JSON config. But, attackers need control of the input that populates into the format string.

article thumbnail

Top Single Sign-On (SSO) Solutions for 2022

eSecurity Planet

Thus, vendors hoping to perform well will need to provide cloud-based SSO services. Kerberos, Security Assertion Markup Language (SAML) , OAuth and OpenID Connect (OIDC) are some of the common federation technologies. Adds risk and fraud signals as well as SSO capabilities. 1,400+ SAML and OpenID Connect integrations.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

What Is API Security? Definition, Fundamentals, & Tips

eSecurity Planet

API Security Standards Modern API security is built on best practices, monitoring, and industry standards like Open Authentication (OAuth) and OpenID Connect, both of which play specific roles in strengthening your digital space. Security Misconfigurations Improperly configured APIs are a major source of security vulnerabilities.

article thumbnail

Administrator's Guide, Part 4: Phases of a Passwordless Rollout

Duo's Security Blog

This may take the form of single sign-on (SSO) or federated portals through standard protocols like Security Assertion Markup Language (SAML) and OpenID Connect (OIDC). Ensure user authentication is occurring from known and trusted devices with up-to-date software and operating systems.