LinkedIn Website
LinkedIn is now patched.
LinkedIn supplied the account’s email addresses as part of the social login authentication process even when the user’s ownership of this email address had not been positively verified. This allowed for a social login attack as detailed in the paper.