RootCauseunvalidated
it is an oracle that returns the username of an encrypted JWT — make the encryption key available to another system in your infrastructure. Tension: there is no way for the client to validate that. Outcome: A compromise of that open service woud allow someone to generate valid JWTs.
4c27db5e-1ec9-4955-9406-1f3a96da30ed
it is an oracle that returns the username of an encrypted JWT — make the encryption key available to another system in your infrastructure. Tension: there is no way for the client to validate that. Outcome: A compromise of that open service woud allow someone to generate valid JWTs.