BTC $78,973.87 -0.87%
ETH $2,481.09 -0.04%
BNB $739.69 -1.03%
XRP $1.39 -1.25%
SOL $103.79 -2.17%
TRX $0.3340 -0.39%
DOGE $0.0900 +0.93%
ADA $0.2207 +0.94%
BCH $266.47 +3.97%
LINK $12.93 +4.71%
HYPE $85.49 -3.00%
AAVE $131.96 -0.92%
SUI $0.8134 +1.83%
XLM $0.1920 +3.98%
ZEC $1,161.45 -1.44%
BTC $78,973.87 -0.87%
ETH $2,481.09 -0.04%
BNB $739.69 -1.03%
XRP $1.39 -1.25%
SOL $103.79 -2.17%
TRX $0.3340 -0.39%
DOGE $0.0900 +0.93%
ADA $0.2207 +0.94%
BCH $266.47 +3.97%
LINK $12.93 +4.71%
HYPE $85.49 -3.00%
AAVE $131.96 -0.92%
SUI $0.8134 +1.83%
XLM $0.1920 +3.98%
ZEC $1,161.45 -1.44%

Okta: Fixed a critical security vulnerability that allowed usernames longer than 52 characters to bypass login verification

2024-11-02 21:19:18

ChainCatcher news, identity and access management software provider Okta officially stated that on October 30, 2024, an internal vulnerability was discovered in the AD/LDAP DelAuth when generating cached keys. The Bcrypt algorithm is used to generate cached keys, where we hash the combination string of userId + username + password. Under specific conditions, this can allow users to authenticate simply by providing a previously successfully authenticated stored cached key to the username.

The prerequisite for this vulnerability is that the username must be equal to or exceed 52 characters each time a cached key is generated for the user. The affected products and versions are Okta AD/LDAP DelAuth as of July 23, 2024, and this vulnerability has been resolved in Okta's production environment on October 30, 2024.

Связанные теги
Связанные теги
app_icon
ChainCatcher Building the Web3 world with innovations.