Millions of airline customers possibly affected by OAUTH SECURITY ERROR


  • A travel service, integrated into many providers of carriers, transported a security error
  • This can be abused to log in to people’s accounts and change their bookings
  • It has since been reported and mitigated

A “popular, top-tier” travel service for hotel and car rental was vulnerable to a mistake that allowed malicious actors to take over anyone’s account, a new report from the API security company Salt Labs has claimed.

By abusing the error, they would be able to book hotel rooms, rent cars and change all booking information, easily. To make things worse, as the service is integrated into “dozens” by commercial airline’s online services, it would also allow misunderstandings to use the airline’s loyalty point and more.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top