The Atlassian OAuth Disaster Nobody’s Talking About

TL;DR: Atlassian 3LO tokens aren’t bound to the specific resource the user consents to. They can expose access to multiple Jira instances — even ones the user never approved — and there’s no way to tell the difference. https://medium.com/@ringr8870/the-atlassian-oauth-disaster-nobodys-talking-about-559eb4dc5767

Apr 20, 2025 - 07:13
 0
The Atlassian OAuth Disaster Nobody’s Talking About

TL;DR: Atlassian 3LO tokens aren’t bound to the specific resource the user consents to. They can expose access to multiple Jira instances — even ones the user never approved — and there’s no way to tell the difference.

https://medium.com/@ringr8870/the-atlassian-oauth-disaster-nobodys-talking-about-559eb4dc5767