← Blog // TAG

JWT

1 article

JWT: the 3 flaws I see in every pentest A JWT is readable without a key (it is not encrypted). The three flaws that turn it into full compromise: alg:none, wea… Read →