Collected research
Three New Attacks Against JSON Web Tokens
Three JWT library flaws: a token encrypted to the public half of a signing key pair is accepted as authentic, a JSON-serialized JWS smuggles unsigned claims past a validator that splits the token on dots, and a PBES2 header with a huge iteration count burns CPU before any authentication tag is checked. The first two forge arbitrary tokens; the third is a denial of service.
Record
- Researcher
- Tom Tervoort
- Published by
- i.blackhat.com
- Format
- Whitepaper
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Tom Tervoort, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .