Redirect-based OAuth Token Exposure in Bitbucket Integrations
An OAuth redirection-based access token leak affecting users of ONA who authenticated using Bitbucket was discovered. The attack relies on several technical details across ONA, Bitbucket, and browser behavior.




