A vulnerability that exposed millions of airline customers to potential account takeovers has highlighted the significant risks organizations face from misconfigured OAuth authentication processes. The vulnerability in this case involved a major provider of online travel services for hotels and car rentals. Many airlines have integrated this service into their websites, allowing customers to use their airline points to book not just flights, but also hotels and rental cars in one seamless process. Researchers at Salt Security, hunting for real-world examples of API supply chain attacks, stumbled upon a vulnerability in the travel company's process for authenticating users looking to access its services after making an initial airline booking. The flaw, which the travel services company has since fixed, basically gave attackers a way to redirect a user's OAuth credentials to a server of their choice. The credentials would have allowed the attackers to obtain a valid session token from an airline's website and use it to log into the travel company's systems as the victim and book hotels and car rentals using airline loyalty points. The discovered vulnerability enabled attackers to hijack victim accounts with a single click, Salt Security researcher Amit Elbirt wrote in a blog post this week, without revealing the identity of the travel services company. While the takeover would have happened within the travel provider's service, it would have given an attacker full access to a ...
OAuth Flaw Exposed Millions of Airline Users to Account Takeovers
Dark Reading
·Jai Vijayan
·Published Jan 28, 2025
·Updated
Affected Software
5 affected components
Booking.com online travel service
Grammarly authentication system
Vidio authentication system
Bukalapak e-commerce site
Major Provider Online Travel Services
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a vulnerability in OAuth authentication that exposed millions of airline users to account takeover risks.
2
What security implications are discussed in the article?
The article highlights the risks associated with misconfigured OAuth authentication processes that can lead to unauthorized access.
3
What products or software are affected by this vulnerability?
The affected products include Booking.com, Grammarly, Vidio, Bukalapak, and a major provider of online travel services.
4
What are the potential consequences of this OAuth flaw?
The OAuth flaw could result in unauthorized account access, compromising sensitive user information.
5
How does the article suggest organizations mitigate this risk?
The article implies that organizations need to ensure proper configuration and security assessments of their OAuth authentication systems.