
CS50 Cybersecurity final project — Palo Alto OAuth token breach (CVE-2024-3400)
Title: The Salesloft OAuth Breach & CVE-2024-3400 (Palo Alto impact)
Author: Yafiya Darwesh (GitHub: Yafiah-Darwesh)
YouTube video: https://youtu.be/CxQNj9qWoZ0?si=cHCwuTIY26YHJ8aw
CVE: CVE-2024-3400
presentation.pdf — slidesscript.txt — speaker notesShort: Misconfigured OAuth token validation allowed token forging and unauthorized access across OAuth integrations (impacting Palo Alto, Cloudflare, Zscaler, etc).
(Contact: [email protected])