










The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.
Customers using the Okta Hyperdrive Integration plugin versions 1.2.0 through 1.5.1 are affected.
This applies if the following preconditions are present:
The agent was installed with the OAuth client secret passed as an MSI property on the installer command line,
A user has local authenticated access on the Windows host where the agent was installed.
To remediate this vulnerability, upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.
Download version 1.5.2 of the Okta Hyperdrive Integration plugin
The vulnerability is present in the Okta Hyperdrive Integration plugin versions 1.2.0 to 1.5.1 and has been resolved in version 1.5.2.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。