Edit: As the article itself stated, around 25% of all systems with this setup are vulnerable!
> The results surprised us: 25% of all the multi-tenant apps we scanned were vulnerable to authentication bypass.
Edit: As the article itself stated, around 25% of all systems with this setup are vulnerable!
> The results surprised us: 25% of all the multi-tenant apps we scanned were vulnerable to authentication bypass.
If only. How about: just download the backup of the server log from https://example.com/logfile.txt? Oh, and it contains everything. Including internal application logs.
In general, one should always use roles in Azure. Even if you have a flaw like this, your endpoint would be safe if you required a role to access your endpoint.
For multi-tenants, I completely this misconfiguration, there’s no real warnings when configuring it. In order to lock down to specific tenants, I recommend having a list of issuers that you check the token against.[2]
[1] https://intility.github.io/fastapi-azure-auth/single-tenant/...
[2] https://intility.github.io/fastapi-azure-auth/multi-tenant/a...