Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Okta Auth0 JWT vulnerability CVE-2022-23529 (github.com/advisories)
7 points by KingOfCoders on Jan 11, 2023 | hide | past | favorite | 2 comments


You can find the original writeup here: https://unit42.paloaltonetworks.com/jsonwebtoken-vulnerabili...

It's pretty much yet another one one the pile of object deserialization vulnerabilities.


I don't see anything about deserialization. If you can add a function to an object, then you're running code on the server already, there's no need to wait for the function to be called. Surely I'm missing some scenario where this is impactful.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: