The CamelHive Standard · v3.25.0
CH-SEC-031v3.25.0La validación de JWT verifica issuer (iss) y audience (aud) entre distintos emisores, y verifica el tipo/propósito del token (typ/purpose) cuando el MISMO emisor firma tokens de distinto uso
Pinned as it read in catalog v3.25.0 — the current version of this rule may read differently, see CH-SEC-031.
- Area
- SEC
- Severity
- high
- Detection
- llm
- Corpus coverage
- not measured by the corpus