Security issue Jamf Connect- Potential to break login to gain browser access, exfil data

jhwang
New Contributor

Was able to do the following while exploring Microsoft Entra Github login option.
Has anyone encountered this? Any solutions out there to prevent?

 

jamfconnect-01.jpgjameconnect-02.jpg

2 REPLIES 2

AJPinto
Honored Contributor III

This would be a Microsoft Entra Problem not Jamf Connect. If Microsoft is presenting a full navigable website, that is on them.

OGClayton
New Contributor III

You can disable sign in with Github through Entra. That should be off organization wide.