← BACK TO FEED
[CRITICAL]2025-11-02Write-ups

Auth bypass chain in legacy SSO middleware

> Chained SSRF + JWT alg confusion to forge admin sessions. Patch path documented.

SSRFJWTSSO

During a web app assessment, an internal SSO helper accepted unsigned JWTs when alg=none was presented.

Combined with an SSRF sink in the avatar proxy, tokens could be minted for any subject claim.

Remediation: enforce RS256 only, disable alg=none, and block link-local ranges on the proxy.