Scan to download
BTC $59,394.66 -0.45%
ETH $1,587.06 +1.09%
BNB $552.29 +0.35%
XRP $1.04 +0.77%
SOL $73.95 +3.86%
TRX $0.3195 -0.73%
DOGE $0.0723 -0.06%
ADA $0.1444 +0.44%
BCH $199.33 +2.82%
LINK $7.30 +0.38%
HYPE $66.14 +6.92%
AAVE $89.93 -3.18%
SUI $0.6928 +1.19%
XLM $0.1858 +7.88%
ZEC $399.92 +6.14%
BTC $59,394.66 -0.45%
ETH $1,587.06 +1.09%
BNB $552.29 +0.35%
XRP $1.04 +0.77%
SOL $73.95 +3.86%
TRX $0.3195 -0.73%
DOGE $0.0723 -0.06%
ADA $0.1444 +0.44%
BCH $199.33 +2.82%
LINK $7.30 +0.38%
HYPE $66.14 +6.92%
AAVE $89.93 -3.18%
SUI $0.6928 +1.19%
XLM $0.1858 +7.88%
ZEC $399.92 +6.14%

Okta: Fixed a critical security vulnerability that allowed usernames longer than 52 characters to bypass login verification

2024-11-02 21:19:18
Collection

ChainCatcher news, identity and access management software provider Okta officially stated that on October 30, 2024, an internal vulnerability was discovered in the AD/LDAP DelAuth when generating cached keys. The Bcrypt algorithm is used to generate cached keys, where we hash the combination string of userId + username + password. Under specific conditions, this can allow users to authenticate simply by providing a previously successfully authenticated stored cached key to the username.

The prerequisite for this vulnerability is that the username must be equal to or exceed 52 characters each time a cached key is generated for the user. The affected products and versions are Okta AD/LDAP DelAuth as of July 23, 2024, and this vulnerability has been resolved in Okta's production environment on October 30, 2024.

app_icon
ChainCatcher Building the Web3 world with innovations.