Algorithm confusion
A JWT attack where the server trusts the token's header to choose how to verify the signature, including the insecure "none" algorithm.
A JWT attack where the server trusts the token's header to choose how to verify the signature, including the insecure "none" algorithm.