Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery
Jingcheng Yang, Enze Wang, Jianjun Chen, Qi Wang, Yuheng Zhang, Haixin Duan, Wei Xie, Baosheng Wang
摘要
—JSON Web Tokens (JWT) have become a widely adopted standard for secure information exchange in modern distributed web applications, particularly for authentication and authorization scenarios. However, JWT implementations have introduced various vulnerabilities, such as signature verification bypass, token spoofing, and denial-of-service attacks. While prior research has reported individual such vulnerabilities, there is a lack of systematic study for JWT implementations. In this paper, we propose JWTeemo, a novel testing methodology to effectively discover JWT vulnerabilities in JWT implementations. We evaluated JWTeemo against 43 JWT implementations across 10 popular programming languages and discovered 31 previously unknown security vulnerabilities, 20 of which have been assigned CVE numbers. We demonstrated the security impact of these vulnerabilities, such as enabling authentication bypass in Kubernetes and denial-of-service attacks against Apache James. We further categorized these vulnerabilities into five types, and proposed several mitigation strategies. We discussed our mitigation strategies with the IETF, which has acknowledged our findings and suggested that they would adopt our mitigations in a new RFC document. We have also reported those identified vulnerabilities to the affected providers and received acknowledgments and bug bounty rewards from Apache, Connect2id, Kubernetes, Let’s Encrypt, and RedHat.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- NEZHA: Efficient Domain-Independent Differential TestingTheofilos Petsios, Adrian Tang, Salvatore J. Stolfo, Angelos D. Keromytis 等S&P 2017 · 被引用 132 次
- Rampart: Protecting Web Applications from CPU-Exhaustion Denial-of-Service AttacksWei Meng, Chenxiong Qian, Shuang Hao, Kevin Borgolte 等USENIX Security 2018 · 被引用 32 次
- Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application FirewallsQi Wang, Jianjun Chen, Zheyu Jiang, Run Guo 等S&P 2024 · 被引用 11 次
- Inbox Invasion: Exploiting MIME Ambiguities to Evade Email Attachment DetectorsJiahe Zhang, Jianjun Chen, Qi Wang, Hangyu Zhang 等CCS 2024 · 被引用 2 次
- ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based FuzzingLinkai Zheng, Xiang Li, Chuhan Wang, Run Guo 等NDSS 2024
相关 Paper
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 被引用 5 次
- Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web ApplicationsQiyi Zhang, Fengyu Liu, Zihan Lin, Yuan ZhangCCS 2025
- Analyzing the WebRTC Ecosystem and Breaking Authentication in DTLS-SRTPMartin Bach, Vukašin Karadžić, Lukas Knittel, Robert Merget 等USENIX Security 2026
- Cookie Crumbles: Breaking and Fixing Web Session IntegrityMarco Squarcina, Pedro Adão, Lorenzo Veronese, Matteo MaffeiUSENIX Security 2023
- Effective Directed Fuzzing with Hierarchical Scheduling for Web Vulnerability DetectionZihan Lin, Yuan Zhang, Jiarun Dai, Xinyou Huang 等USENIX Security 2025
