Abusing JWT public keys without the public key(blog.silentsignal.eu)
blog.silentsignal.eu
Abusing JWT public keys without the public key
https://blog.silentsignal.eu/2021/02/08/abusing-jwt-public-keys-without-the-public-key/
https://blog.silentsignal.eu/2021/02/08/abusing-jwt-public-keys-without-the-public-key/
... that might be why they are called "public" keys