









The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.
Customers using the Okta Privileged Access client versions 1.18.0 through 1.112.0 are affected.
To remediate this vulnerability, upgrade the Okta Privileged Access client to version 1.113.0.
The vulnerability is present in the Okta Privileged Access client versions 1.18.0 to 1.112.0 and resolved in Okta Privileged Access client version 1.113.0.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。