Markdown Version | Session Recording

Session Date/Time: 27 Jan 2025 17:00

OAUTH

Summary

This interim meeting focused on a newly identified security vulnerability in the Private Key JWT client authentication method. The vulnerability stems from ambiguities in the aud (audience) claim definition across several OAuth and OpenID Connect specifications, potentially allowing an attacker to replay client assertions. The discussion covered the technical details of the attack, its preconditions, proposed mitigations, and the necessary updates to affected specifications. Key points of debate included the scope of a proposed "bis" document for RFC 7523 and whether to incorporate this vulnerability into the already-published oauth-security-bcp.

Key Discussion Points

Decisions and Action Items

Next Steps