Collected research
Critical Vulnerabilities in JSON Web Token Libraries
Critical vulnerabilities in JSON Web Token libraries
JWT lets the token itself name the algorithm used to verify it, so an attacker chooses the verification method. Many libraries accepted alg none as a validly signed token, and when handed an HS256 token treated the server's RSA public key as the HMAC secret, letting anyone with the public key forge tokens and authenticate as any user.
Record
- Document
- Critical vulnerabilities in JSON Web Token libraries
- Published by
- chosenplaintext.ca
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of chosenplaintext.ca, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .