OneDrive flaw can give websites and apps full access to your files, even if you pick
#1
Exclamation 
Quote:Microsoft OneDrive is used by millions of users, largely thanks to its integration as the default cloud file hosting service on Windows and Microsoft 365.

Security researchers at Oasis Security discovered a flaw in OneDrive that could give services, apps, and websites full access to all hosted files.

Many web services and sites support uploading files directly from OneDrive and other cloud storage services. ChatGPT, to name just one, includes an option to link the account with a OneDrive account for easier file uploads.

The main benefit here is that files can be uploaded directly from the cloud storage service. This is often faster than uploading the files from the local system.

Many users who upload files directly from OneDrive to such a service might expect that it only gains permissions to access the selected file or files.

Oasis Security notes that this is not the case, as OneDrive does not support fine-grained access controls. In other words, it is a all or nothing option that, at least in theory, gives the service full access to all files.

The permissions are time-limited by default but refresh tokens may be used to extend the access period.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.3.10  Added an...Kool — 07:30
Scientists invent entirely new kind of s...
Scientists have inve...schreckdeividas — 07:51
Android trojan posing as government serv...
We break down the ...harlan4096 — 10:18
Brave Release v1.88.127 (Chromium 146.0....
Release v1.88.127 ...harlan4096 — 10:16
AMD reveals “FSR Diamond” for Next-Gen X...
AMD confirms FSR D...harlan4096 — 10:15

[-]
Birthdays
Today's Birthdays
avatar (51)tersfargum
avatar (50)alfreExept
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (38)Charlesfibre
avatar (38)francisnj3
avatar (43)artmaGoork

[-]
Online Staff
There are no staff members currently online.

>