ClusterConcept
Broken Crypto Authentication Practices
cluster-35
Encryption or identity checks get implemented without message authentication or correct key/parameter handling—e.g., AES-CBC without integrity, unmanaged IV/key lifecycles, and insufficient JWKS trust validation—so attackers can tamper, substitute, or replay data and tokens.