|
|
|
|
|
by lovasoa
20 hours ago
|
|
What they conveniently omit in the blog post is what the vulnerability was: it seems like they renewed JWTs without checking the signature at all ! You could write arbitrary info in an old token, and get it signed without any verification. https://www.youtube.com/watch?v=q2KCrmQz9WE |
|