Accidental Exposure of Passwords at Client Site

If the client does not provide enough protection, an attacker or disgruntled employee could retrieve the passwords for a user.

OAuth 2.0 Threat Model and Security Considerations (RFC6819, section


This threat is considered fully mitigated if all the test cases from the following test set succeed.

