Yard App Cookie Flaw Let Testers Impersonate 95 Users
Resecurity’s authorized test found a yard app’s hardcoded session secret let testers impersonate 95 of 241 users, bypassing Entra ID MFA.
During authorized testing, Resecurity found that a supply-chain yard-management platform signed session cookies with a hardcoded secret, allowing forged sessions after Entra ID single sign-on. GBHackers identifies the secret as the HMAC-SHA256 string session_secret_example, while Cyber Security News says only that the hard-coded secret matched the cookie name. Both say the signed value was a public user database identifier and that testers impersonated 95 of 241 accounts, including elevated users, without passwords, MFA, or valid Entra ID tokens. Cyber Security News adds that a forged administrator session completed a state-changing API call and that an unauthenticated Swagger interface exposed 251 routes. GBHackers adds that /api/v1/auth/me returned Entra refresh tokens. Sources agree Entra ID itself was not broken and do not report criminal exploitation; one says production systems were not tested.
- Resecurity found the issue in authorized testing of a supply-chain yard-management platform; it was not described as criminal exploitation, and one source said no production systems were tested.
- Session cookies used a hardcoded signing secret. GBHackers names HMAC-SHA256 and the literal secret session_secret_example; Cyber Security News says the secret matched the cookie name.
- The signed cookie value was a publicly exposed user database identifier.
- Testers impersonated 95 of 241 accounts, including administrators or other elevated users, without passwords, MFA, or valid Microsoft Entra ID tokens.
- Cyber Security News said a forged administrator session completed a state-changing API call.
- GBHackers said the /api/v1/auth/me endpoint returned Entra refresh tokens.
- Cyber Security News said an unauthenticated Swagger interface exposed 251 API routes.
- Researchers said Entra ID cryptography was not broken and the flaw was in the application session layer.
Coverage timelineoldest first · each row is one article
- · 12h agoAuthentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA
GBHackers· 50
Testers forged session cookies on a yard-management app and impersonated 95 users without passwords or MFA.
- · 11h agoSession Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users
Cyber Security News· 52
Resecurity found a yard-management app’s forged session cookies bypassed Entra ID MFA and impersonated users.