gchq/CyberChef
Ver no GitHubBug report: JWT Verify doesn't require an algorithm
Open
#624 aberto em 27 de ago. de 2019
featurehelp wanted
Métricas do repositório
- Stars
- (34.843 stars)
- Métricas de merge de PR
- (Mesclagem média 57d 13h) (62 fundiu PRs em 30d)
Description
As detailed here, JWT verification functions should require specifying the algorithm that should have been used, in order to prevent an attacker from changing the algorithm to a symmetric algorithm from an asymmetric one and using the public key to sign the token. Probably low priority for this particular app, but it would be good to at least have the option.