Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Dojo challenge #52 Streamcore solution

Summary

Dojo challenge #52 Streamcore solution: the JWT handler trusts the unsigned 'kid' header before signature checks; path traversal reads /tmp/README.txt, whose contents sign an admin token.
Published
Collected

original ↗

Related coverage

back