










The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.
Customers using the Okta Hyperdrive Integration plugin versions 1.2.0 through 1.5.1 are affected.
This applies if the following preconditions are present:
A user has local authenticated access on the Windows host as an unprivileged interactive user,
The user can write to the per-user registry hive that assembly resolution falls through to,
Assembly resolution falls through the standard system-wide (HKLM) path.
To remediate this vulnerability, upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.
Download version 1.5.2 of the Okta Hyperdrive Integration plugin
The vulnerability is present in Okta Hyperdrive Integration plugin versions 1.2.0 to 1.5.1 and has been resolved in version 1.5.2.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。