Critical Auth Bypass in pac4j-jwt: Full PoC Using Only a Public Key (opens in new tab)
We found a critical authentication bypass in pac4j-jwt where an attacker can impersonate any user using only the RSA public key. Full PoC and disclosure.
Read the original article