BTC $62,940.18 -0.01%
ETH $1,878.36 +0.05%
BNB $606.12 -0.80%
XRP $0.9987 -0.33%
SOL $75.16 -0.07%
TRX $0.3311 -0.06%
DOGE $0.0696 -0.39%
ADA $0.1758 -1.68%
BCH $203.57 -0.71%
LINK $9.40 +0.72%
HYPE $57.44 +2.60%
AAVE $85.76 -1.51%
SUI $0.6763 -1.04%
XLM $0.1568 -0.93%
ZEC $485.38 -0.71%
BTC $62,940.18 -0.01%
ETH $1,878.36 +0.05%
BNB $606.12 -0.80%
XRP $0.9987 -0.33%
SOL $75.16 -0.07%
TRX $0.3311 -0.06%
DOGE $0.0696 -0.39%
ADA $0.1758 -1.68%
BCH $203.57 -0.71%
LINK $9.40 +0.72%
HYPE $57.44 +2.60%
AAVE $85.76 -1.51%
SUI $0.6763 -1.04%
XLM $0.1568 -0.93%
ZEC $485.38 -0.71%

Okta: Fixed a critical security vulnerability that allowed usernames longer than 52 characters to bypass login verification

2024-11-02 21:19:18

ChainCatcher news, identity and access management software provider Okta officially stated that on October 30, 2024, an internal vulnerability was discovered in the AD/LDAP DelAuth when generating cached keys. The Bcrypt algorithm is used to generate cached keys, where we hash the combination string of userId + username + password. Under specific conditions, this can allow users to authenticate simply by providing a previously successfully authenticated stored cached key to the username.

The prerequisite for this vulnerability is that the username must be equal to or exceed 52 characters each time a cached key is generated for the user. The affected products and versions are Okta AD/LDAP DelAuth as of July 23, 2024, and this vulnerability has been resolved in Okta's production environment on October 30, 2024.

app_icon
ChainCatcher Building the Web3 world with innovations.