Scan to download
BTC $69,471.38 -4.30%
ETH $1,978.46 -0.12%
BNB $678.64 -3.65%
XRP $1.26 -3.16%
SOL $79.22 -2.22%
TRX $0.3404 -2.77%
DOGE $0.0990 -0.99%
ADA $0.2239 -3.22%
BCH $284.98 +0.30%
LINK $8.84 -1.93%
HYPE $72.23 -0.20%
AAVE $77.98 -4.01%
SUI $0.8472 -3.60%
XLM $0.2322 -12.90%
ZEC $577.41 +6.02%
BTC $69,471.38 -4.30%
ETH $1,978.46 -0.12%
BNB $678.64 -3.65%
XRP $1.26 -3.16%
SOL $79.22 -2.22%
TRX $0.3404 -2.77%
DOGE $0.0990 -0.99%
ADA $0.2239 -3.22%
BCH $284.98 +0.30%
LINK $8.84 -1.93%
HYPE $72.23 -0.20%
AAVE $77.98 -4.01%
SUI $0.8472 -3.60%
XLM $0.2322 -12.90%
ZEC $577.41 +6.02%

Okta: Fixed a critical security vulnerability that allowed usernames longer than 52 characters to bypass login verification

2024-11-02 21:19:18
Collection

ChainCatcher news, identity and access management software provider Okta officially stated that on October 30, 2024, an internal vulnerability was discovered in the AD/LDAP DelAuth when generating cached keys. The Bcrypt algorithm is used to generate cached keys, where we hash the combination string of userId + username + password. Under specific conditions, this can allow users to authenticate simply by providing a previously successfully authenticated stored cached key to the username.

The prerequisite for this vulnerability is that the username must be equal to or exceed 52 characters each time a cached key is generated for the user. The affected products and versions are Okta AD/LDAP DelAuth as of July 23, 2024, and this vulnerability has been resolved in Okta's production environment on October 30, 2024.

app_icon
ChainCatcher Building the Web3 world with innovations.