Smartersoft B.V. is addressing a security flaw in the dotnet core framework by implementing Option A, where JWT authentication should validate a semantically valid JWT using an invalid authority.
Public source
Publisher name
Public post
I found a serious #security flaw in #dotnet. What do you think should happen when you misconfigure the authority of your JWT authentication? Option A: Application should…
Company
Smartersoft B.V.
Syncing data between apps
- Industry
- Software Development
- Location
- Eindhoven, NL
- Company size
- 1 employee
About Smartersoft B.V.
Smartersoft B.V. is a Dutch Software company, specialized in synchronizing data between third-party applications. We also develop custom API with our customers.
See moreDiscover more
Similar signals
Similar public activity from other companies.
Products & Services
TestifySec
TestifySec is developing a time-limited JWT authorized by a human at AAL2 for delegating authority to agents.
Products & Services
comforte AG
comforte AG believes that data protection is not a hindrance to data sharing but rather an enabler for safe and secure use and reuse of sensitive data.
Products & Services
Cyber Solutions Luxembourg
Cyber Solutions Luxembourg highlights GitHub Actions OIDC tokens that can carry immutable identifiers in the sub claim, which breaks trust policies matching on names.
Products & Services
Kerno
Kerno introduced a security testing mode that can catch complex runtime issues like IDOR and BOLA, with the ability to handle extra identity, roles, and user permissions, manage the deterministic data layer, and provide evidence and artefacts for testing.
Products & Services
Descope