惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
雷峰网
雷峰网
The Cloudflare Blog
WordPress大学
WordPress大学
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
IT之家
IT之家
V
V2EX
博客园 - 司徒正美
小众软件
小众软件
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
Last Week in AI
Last Week in AI
Jina AI
Jina AI
博客园 - 叶小钗
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿

Okta Trust

Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe
Okta Advanced Server Access Client CVE-2022-24295
Okta, Inc. · 2022-02-17 · via Okta Trust

Description

Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.

Affected product and versions

Okta Advanced Server Access Client for Windows prior to version 1.57.0.

Resolution

The vulnerability is fixed in Okta Advanced Server Access Client for Windows version 1.57.0. To remediate this vulnerability, upgrade Okta Advanced Server Access Client for Windows.

CVE details

CVE ID

CVE-2022-24295

Published Date

2022-02-17

Vulnerability Type

Remote Code Execution

CWE

CWE-94

CVSS v3

Score:8.8

Vector string:AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Acknowledgements

Okta would like to thank their partner Andreas Lindh at Recurity Labs for assistance on this finding.

Okta’s priority is always platform security and customer trust. Okta’s vulnerability management program uses a variety of methods to identify and fix security issues. When we score vulnerabilities we leverage the CVSS version 3.1 framework.

Legal Disclaimer:

The information provided in Okta’s Security Advisories is provided "as is" without warranty of any kind. Okta disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Okta or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Okta or its suppliers have been advised of the possibility of such damages. The foregoing exclusions will not apply to the extent prohibited by applicable law.

References

Install and enroll the Okta Advanced Service Access client on Windows