Scan to download
BTC $60,914.26 +0.03%
ETH $1,563.21 -2.72%
BNB $576.42 -1.55%
XRP $1.11 +0.22%
SOL $62.78 -3.66%
TRX $0.3207 -1.11%
DOGE $0.0823 -0.82%
ADA $0.1611 -0.12%
BCH $219.14 -0.41%
LINK $7.41 -0.17%
HYPE $58.69 -4.52%
AAVE $61.07 -1.44%
SUI $0.7234 +2.10%
XLM $0.2043 +7.32%
ZEC $347.83 +7.16%
BTC $60,914.26 +0.03%
ETH $1,563.21 -2.72%
BNB $576.42 -1.55%
XRP $1.11 +0.22%
SOL $62.78 -3.66%
TRX $0.3207 -1.11%
DOGE $0.0823 -0.82%
ADA $0.1611 -0.12%
BCH $219.14 -0.41%
LINK $7.41 -0.17%
HYPE $58.69 -4.52%
AAVE $61.07 -1.44%
SUI $0.7234 +2.10%
XLM $0.2043 +7.32%
ZEC $347.83 +7.16%

Okta: Fixed a critical security vulnerability that allowed usernames longer than 52 characters to bypass login verification

2024-11-02 21:19:18
Collection

ChainCatcher news, identity and access management software provider Okta officially stated that on October 30, 2024, an internal vulnerability was discovered in the AD/LDAP DelAuth when generating cached keys. The Bcrypt algorithm is used to generate cached keys, where we hash the combination string of userId + username + password. Under specific conditions, this can allow users to authenticate simply by providing a previously successfully authenticated stored cached key to the username.

The prerequisite for this vulnerability is that the username must be equal to or exceed 52 characters each time a cached key is generated for the user. The affected products and versions are Okta AD/LDAP DelAuth as of July 23, 2024, and this vulnerability has been resolved in Okta's production environment on October 30, 2024.

app_icon
ChainCatcher Building the Web3 world with innovations.