Issue 209: CSRF in Plesk API-enabled server, top five API security myths, Ory Hydra authentication server
Brief
This week, we have new research from FORTBRIDGE that reveals a client-side request forgery (CSRF) vulnerability in API-enabled instances of Plesk, the popular server administration portal. We also have an article on the top five API security myths according to Hacker News, a quick look at the Ory Hydra OAuth2/OIDC server, and a guide to some awesome BurpSuite extensions.
Vulnerability: CSRF in Plesk API-enabled server
First up this week is breaking research from our friends at FORTBRIDGE which uncovered a CSRF vulnerability in the REST API of the popular server administration tool, Plesk. Plesk is widely used as an administrative front-end for web hosting and data center providers, and has generally been hardened and patched against security vulnerabilities.
