Web Hack List

Later archive addition

Critical Vulnerabilities in JSON Web Token Libraries

JWT lets the token itself name the algorithm used to verify it, so an attacker chooses the verification method. Many libraries accepted alg none as a validly signed token, and when handed an HS256 token treated the server's RSA public key as the HMAC secret, letting anyone with the public key forge tokens and authenticate as any user.

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.