BTC $79,232.31 -0.85%
ETH $2,494.90 -0.17%
BNB $739.74 -1.56%
XRP $1.40 -1.58%
SOL $104.09 -1.55%
TRX $0.3345 -0.43%
DOGE $0.0906 +0.44%
ADA $0.2210 +0.04%
BCH $260.58 +1.03%
LINK $12.78 -2.27%
HYPE $85.30 -3.04%
AAVE $132.43 -0.73%
SUI $0.8322 +3.03%
XLM $0.1928 +4.11%
ZEC $1,155.60 -5.03%
BTC $79,232.31 -0.85%
ETH $2,494.90 -0.17%
BNB $739.74 -1.56%
XRP $1.40 -1.58%
SOL $104.09 -1.55%
TRX $0.3345 -0.43%
DOGE $0.0906 +0.44%
ADA $0.2210 +0.04%
BCH $260.58 +1.03%
LINK $12.78 -2.27%
HYPE $85.30 -3.04%
AAVE $132.43 -0.73%
SUI $0.8322 +3.03%
XLM $0.1928 +4.11%
ZEC $1,155.60 -5.03%

Okta: Fixed a critical security vulnerability that allowed usernames longer than 52 characters to bypass login verification

2024-11-02 21:19:18

ChainCatcher news, identity and access management software provider Okta officially stated that on October 30, 2024, an internal vulnerability was discovered in the AD/LDAP DelAuth when generating cached keys. The Bcrypt algorithm is used to generate cached keys, where we hash the combination string of userId + username + password. Under specific conditions, this can allow users to authenticate simply by providing a previously successfully authenticated stored cached key to the username.

The prerequisite for this vulnerability is that the username must be equal to or exceed 52 characters each time a cached key is generated for the user. The affected products and versions are Okta AD/LDAP DelAuth as of July 23, 2024, and this vulnerability has been resolved in Okta's production environment on October 30, 2024.

app_icon
ChainCatcher Building the Web3 world with innovations.