Tech

Millions of airline customers possibly affected by OAuth security flaw

Share
Share


  • A travel service, integrated into many airline service providers, carried a security flaw
  • This could be abused to log into people’s accounts and change their bookings
  • It has since been reported and mitigated

A “popular, top-tier” travel service for hotel and car rentals was vulnerable to a flaw which allowed malicious actors to take over anyone’s account, a new report from API security firm Salt Labs has claimed.

By abusing the flaw, they would be able to book hotel rooms, rent cars, and modify any booking information, easily. To make matters worse, since the service is integrated into “dozens” of commercial airline online services, it would also allow miscreants to spend airline loyalty points, and more.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Comino teams up with Puget systems so you can buy silent dual-CPU, 8-GPU rack workstations for much cheaper
Tech

Comino teams up with Puget systems so you can buy silent dual-CPU, 8-GPU rack workstations for much cheaper

Comino Grando Server delivers extreme GPU performance for deep learning tasks High-speed...

Elecom’s 9,000mAh sodium-ion battery is costly and bulky but it will last longer and is much safer than lithium-ion ones
Tech

Elecom’s 9,000mAh sodium-ion battery is costly and bulky but it will last longer and is much safer than lithium-ion ones

Elecom’s 9,000mAh sodium-ion battery offers superior safety and longevity The first sodium-ion...

Basalt fabric-based cathode enhances solar-powered wastewater treatment
Tech

Basalt fabric-based cathode enhances solar-powered wastewater treatment

(A) Fabrication of the BF-CNT/AgNWs composite cathode material; (B) Experimental setup of...