漏洞描述
The OpenID Connect discovery document advertises "none" among its id_token_signing_alg_values_supported, meaning the authorization server is willing to issue ID tokens with no signature. A relying party that accepts such a token cannot verify its integrity, enabling JWT "alg:none" forgery and authentication bypass. The "none" algorithm should never be offered for ID tokens in production.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。