jwt_tool icon indicating copy to clipboard operation
jwt_tool copied to clipboard

CVE-2020-28637 - more details?

Open attritionorg opened this issue 4 years ago • 1 comments

Following up from Twitter, hoping to get more details on CVE-2020-28637. Thanks! (tag @ticarpi)

attritionorg avatar Feb 09 '21 18:02 attritionorg

There's been a hold up in publication, so I can't reveal the vulnerable application. For now I can say that the exploit is an alternative signing method for JWTs signed with a Private Key, where symmetric signing is enabled by default, but the secret is not set. So in practice you can sign new JWTs with a blank secret and forge your own tokens.

ticarpi avatar Feb 23 '21 20:02 ticarpi