SaaS Apps Still Vulnerable: nOAuth Misconfiguration Madness Continues!

More than 10,000 SaaS apps could still be vulnerable to a nOAuth variant, despite the issue being disclosed in June 2023. Even with Microsoft’s guidance, this misconfiguration remains unfixable by them, leaving developers to bear the burden. Remember, nOAuth: where the only thing harder than pronouncing it is fixing it.

Pro Dashboard

Hot Take:

Just when you thought your SaaS apps were safe, nOAuth slides in like a sneaky raccoon rifling through your trash! Turns out, more than 10,000 SaaS apps might be rolling out the welcome mat to this mischievous variant. With all the excitement of watching paint dry, Microsoft has decided to play the role of a wise old sage, offering advice from the mountaintop, while developers continue to wander aimlessly in the valley of potential misconfigurations. Who knew securing the digital frontier would be this thrilling?

Key Points:

  • nOAuth is a sneaky misconfiguration abuse in SaaS apps interfacing with Entra ID.
  • More than 10,000 SaaS apps might be open to nOAuth attacks despite a prior warning.
  • Microsoft offers advice, but developers are the key players in preventing nOAuth.
  • Semperis research indicates a 9% vulnerability rate in tested SaaS apps.
  • nOAuth is a misconfiguration issue, not a fixable vulnerability.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?