Day8/
#30daysofAPIsec
I ran jwt_tool against crAPI's dashboard endpoint and discovered the JWT implementation is critically broken itaccepts invalid signatures, unsigned tokens (alg:none),forged JWKS, and SQL injection in the kid claim. Almost every major JWT attack returned 200