I think they address some important issues, but all of them can me mitigated or exist in session cookies, too: https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-bad-standard-that-everyone-should-avoid