BTC $77,347.53 -2.01%
ETH $2,417.52 -2.47%
BNB $680.41 -1.65%
XRP $1.35 -2.61%
SOL $100.01 -3.89%
TRX $0.3231 -3.09%
DOGE $0.0818 -1.66%
ADA $0.1959 -1.56%
BCH $246.31 -0.59%
LINK $11.22 -1.45%
HYPE $82.71 -1.86%
AAVE $125.92 +1.46%
SUI $0.7218 -0.94%
XLM $0.1761 -1.94%
ZEC $824.20 -3.45%
BTC $77,347.53 -2.01%
ETH $2,417.52 -2.47%
BNB $680.41 -1.65%
XRP $1.35 -2.61%
SOL $100.01 -3.89%
TRX $0.3231 -3.09%
DOGE $0.0818 -1.66%
ADA $0.1959 -1.56%
BCH $246.31 -0.59%
LINK $11.22 -1.45%
HYPE $82.71 -1.86%
AAVE $125.92 +1.46%
SUI $0.7218 -0.94%
XLM $0.1761 -1.94%
ZEC $824.20 -3.45%

Okta: Fixed a critical security vulnerability that allowed usernames longer than 52 characters to bypass login verification

2024-11-02 21:19:18

ChainCatcher news, identity and access management software provider Okta officially stated that on October 30, 2024, an internal vulnerability was discovered in the AD/LDAP DelAuth when generating cached keys. The Bcrypt algorithm is used to generate cached keys, where we hash the combination string of userId + username + password. Under specific conditions, this can allow users to authenticate simply by providing a previously successfully authenticated stored cached key to the username.

The prerequisite for this vulnerability is that the username must be equal to or exceed 52 characters each time a cached key is generated for the user. The affected products and versions are Okta AD/LDAP DelAuth as of July 23, 2024, and this vulnerability has been resolved in Okta's production environment on October 30, 2024.

app_icon
ChainCatcher Building the Web3 world with innovations.