json-jwt allows bypass of identity checks via a sign/encryption confusion attack (CVE-2023-51774) | HOL Guard CVE