The verification services company Okta has fixed a vulnerability present in its system since July that allowed access to it without the need for a password as long as users entered a name was 52 or more characters long.
Okta is a system used by several organizations and governments in different parts of the world as a single sign-on provider, a service that provides greater security when accessing internal company systems. Among them, hundreds of emails and applications or databases.
The third-party security firm has announced that on October 30, a vulnerability in the generation of the DelAuth directory server (AD/LDAP) cache key was identified internally, as indicated in a statement.
This flaw, which would have been present in its service since July 23 as an error in part of a standard version of Okta, allowed a user to authenticate in different ways, such as, for example, with the stored cache key of an authentication previous successful.
Likewise, it has advanced that, to exploit the vulnerability, it was necessary for the username to be 52 characters long or more and for the two-factor authentication system (MFA) not to be applied.
Okta has also announced that this error has already been resolved by modifying the cryptographic algorithms and moving from Bcrypt to PBKDF2. Likewise, it has urged its clients to implement the multi-factor authentication system “at a minimum.”
Although it has not confirmed that the vulnerability has been exploited, it has “strongly” recommended that users register their accounts with authenticators that are “resistant” to fraud such as identity theft. For example, FIDO2 WebAuthn.
TryHackMe | Cyber Security Training
airsoftc3.com
My profile – About me – SimonReed – MyOMSYSTEM
freddiehughes's Photo Galleries at pbase.com
DylanCooper | Users | joinDOTA.com
Profile | Archie Cole | GoldPoster
Ver perfil: FinnRogerse – Comunidad N3D
Perfíl de Usuario – eurovision-spain.com
Cannabis.net
Información • Club de Propietarios del Seat Leon
Utherverse Free Dating Adult Social Network – hugoellis' profile
Jack Simpson | Formando Formadores
StanleyHarper | StanleyHarper – Roberts Space Industries | Follow the development of Star Citizen and Squadron 42
TobyCameron (@tobycameron) • BandLab – Make Music Online
Spencer Curtis @SpencerCurtis – MyMiniFactory
CharlieHarrisones's Profile | Nexus Mods
The Yeshiva World
EllisMason – profile – Read Free Manga Online at Bato.To
kitsu.app/users/LukeFleming
JamieMorgans's Shows | Mixcloud
A Whole New Level of Online Gaming – Pastelink.net
forum.acronis.com/user/746945
Jay Collins (JayCollins) | wallmine
Buy Beats Online | Download Beats | Rap Beats For Sale | Instrumentals For Sale
Cadillac Society
nepris.com/app/user/3712858
Oliver Fletcher — Hashnode
About roryblakes12 – Twitch
Пользователь Felix FelixHudson Hudson
Pin-Up World(RU): Другие компании в регионе Москва | homify