View Issue Details

IDProjectCategoryView StatusLast Update
001010110000-006: MappingsSpecpublic2025-09-25 14:24
ReporterErik Kitzmann Assigned ToRandy Armstrong  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Version1.05.04 
Fixed in Version1.05.06 
Summary0010101: JWT security issue
Description

RFC 7518 allowes a JWT with the signing algorithm "none".
This is a security issue, in my opinion the UA specification should forbid this.

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Randy Armstrong

2025-05-21 07:57

administrator   ~0022756

Added: all Access Tokens shall have a signature created by the token issuer.

Jim Luth

2025-09-25 14:24

administrator   ~0023379

Agreed to changes in F2F meeting.

Issue History

Date Modified Username Field Change
2025-01-16 09:37 Erik Kitzmann New Issue
2025-01-21 18:04 Jim Luth Assigned To => Randy Armstrong
2025-01-21 18:04 Jim Luth Status new => assigned
2025-05-21 07:57 Randy Armstrong Status assigned => resolved
2025-05-21 07:57 Randy Armstrong Resolution open => fixed
2025-05-21 07:57 Randy Armstrong Note Added: 0022756
2025-09-25 14:24 Jim Luth Status resolved => closed
2025-09-25 14:24 Jim Luth Fixed in Version => 1.05.06
2025-09-25 14:24 Jim Luth Note Added: 0023379