Crafting a Full Read SSRF: A Journey Through Oauth DCR, Open URL Redirects, and Path Normalization
The Bug
This blog post outlines the chains of multiple gadgets to achieve a full read ssrf on a target.
Open Dynamic client registration on the MCP server to create an open redirect gadget
Path norm
eib.hashnode.dev8 min read