gchq/CyberChef

Bug report: JWT Verify doesn't require an algorithm

Open

#624 geöffnet am 27. Aug. 2019

Auf GitHub ansehen
 (3 Kommentare) (0 Reaktionen) (0 zugewiesene Personen)JavaScript (34.843 Stars) (3.944 Forks)batch import
featurehelp wanted

Beschreibung

As detailed here, JWT verification functions should require specifying the algorithm that should have been used, in order to prevent an attacker from changing the algorithm to a symmetric algorithm from an asymmetric one and using the public key to sign the token. Probably low priority for this particular app, but it would be good to at least have the option.

Contributor Guide