OneDrive flaw can give websites and apps full access to your files, even if you pick
#1
Exclamation 
Quote:Microsoft OneDrive is used by millions of users, largely thanks to its integration as the default cloud file hosting service on Windows and Microsoft 365.

Security researchers at Oasis Security discovered a flaw in OneDrive that could give services, apps, and websites full access to all hosted files.

Many web services and sites support uploading files directly from OneDrive and other cloud storage services. ChatGPT, to name just one, includes an option to link the account with a OneDrive account for easier file uploads.

The main benefit here is that files can be uploaded directly from the cloud storage service. This is often faster than uploading the files from the local system.

Many users who upload files directly from OneDrive to such a service might expect that it only gains permissions to access the selected file or files.

Oasis Security notes that this is not the case, as OneDrive does not support fine-grained access controls. In other words, it is a all or nothing option that, at least in theory, gives the service full access to all files.

The permissions are time-limited by default but refresh tokens may be used to extend the access period.

Continue Reading...
Reply


Messages In This Thread
OneDrive flaw can give websites and apps full access to your files, even if you pick - by harlan4096 - 03 June 25, 07:30

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Privazer 4.0.19
PrivaZer version v...Kool — 11:15
XYplorer
What's new in Rele...Kool — 11:11
QOwnNotes
25.8.7 In the l...Kool — 11:08
QOwnNotes
25.8.6 When ent...Kool — 13:43
Adguard for Windows, Android, iOS
AdGuard for Window...Kool — 10:43

[-]
Birthdays
Today's Birthdays
avatar (49)DavidDow
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (40)obudyg
avatar (48)rarinsWax
avatar (25)DianaBrown
avatar (35)emyzowa
avatar (46)JustinPrede
avatar (38)eqiduseb
avatar (44)fedosmiday
avatar (41)brechTiz
avatar (47)schedZoorb
avatar (41)bgreorasjunior4824
avatar (45)ThomasLYDAY
avatar (40)upakoExapy
avatar (39)Margieweimi
avatar (39)Larondabet
avatar ()tradedeer1
avatar (50)diplomasync
avatar (49)Myronjax
avatar (49)skepwHug
avatar (38)RicardoGoase
avatar (41)JaniceArods
avatar (42)Brianven
avatar (31)I3rYcE
avatar (42)Edwardgef
avatar (43)Denpokhew
avatar (35)azidony
avatar (40)maskbSleew

[-]
Online Staff
There are no staff members currently online.

>