[CRITICAL]2025-11-02Write-ups
Auth bypass chain in legacy SSO middleware
> Chained SSRF + JWT alg confusion to forge admin sessions. Patch path documented.
SSRFJWTSSO
During a web app assessment, an internal SSO helper accepted unsigned JWTs when alg=none was presented.
Combined with an SSRF sink in the avatar proxy, tokens could be minted for any subject claim.
Remediation: enforce RS256 only, disable alg=none, and block link-local ranges on the proxy.