It has been 1 day since the last alg:none JWT vulnerability.
An attacker could impersonate any user in Microsoft Sharepoint due to the validation only of a signed inner JWT wrapped in an outer JWT that could be alg:none and, hang on, isn't this the exact same thing as the Entra ID one?