Why the long name? Okta discloses auth bypass bug affecting 52-character usernames
ID: 2e2a211b-ea54-5397-b56a-2e8cdd91943f
STIX ID: report--2e2a211b-ea54-5397-b56a-2e8cdd91943f
Feed Name: The Register (Security)
Threat Score
Okta discovered and fixed a Delegated Authentication vulnerability that could let an attacker authenticate using only a username 52 characters or longer when a bcrypt-based cached login key existed and was used (for example if the AD/LDAP agent was unreachable) and multi-factor authentication was not enabled; the issue was found and patched the same day and customers were advised to check logs and enable phishing-resistant MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
