Okta Fixes Auth Bypass Bug After 3-Month Lull
ID: bf4cdf0f-e72f-5d20-b3c3-0d2ed6995824
STIX ID: report--bf4cdf0f-e72f-5d20-b3c3-0d2ed6995824
Feed Name: Dark Reading
Threat Score
Okta patched an AD/LDAP delegated authentication bypass that could allow authentication using only a username when specific conditions were met (including usernames of 52+ characters, a cached prior authentication, and an unreachable AD/LDAP agent). The flaw, found Oct. 30 after roughly three months in the system, has been fixed; Okta advised customers to review logs since July 23 and implement MFA, and it is unclear whether the bug was exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
