tpaidakis
Writeups About Disclosure

Authentication

2024-03-15 2 min read CVE-2024-0001 webauthenticationjwtcritical

Example: Auth Bypass via JWT Algorithm Confusion

A critical authentication bypass in ExampleApp allowed any unauthenticated user to forge valid session tokens by exploiting algorithm confusion in JWT verification.

© 2024–2026 Theo Paidakis · Built with Hugo RSS