Cyber Security Holes of JSON Web Token
Remya Chandran · 2024
JSON Web Token (JWT) is frequently used in information exchange, authentication, and authorization. The most typical application of JWT among these use cases is for authorization. Once logged in, a user can access the routes, services, and resources that are authorized with that token by including the jWi in any subsequent requests. When a user logs in, the server creates a JWT with details about that user, including their user ID and role. After then, the JWT is transmitted back to the client and stored. The server can then check the JWT’s authenticity before processing any ensuing requests that the client sends after that. As a result, there is no requirement for a session state on the server, enabling secure communication between the client and server. Even if JWT is a very popular method used for “single sign-on” nowadays, it faces many challenges. This paper discusses the different identified vulnerabilities of JWT.