logoalt Hacker News

Freak_NLtoday at 7:35 AM0 repliesview on HN

And of course, because the inner JWT is already signed, why bother signing the outer one? Just validate the inner one!

I'm feeling sorry for those poor abused JWTs in this vulnerability.