Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.
2022-03-23T20:15:10.757
2024-11-21T06:39:53.480
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | okta | advanced_server_access | < 1.58.0 | Yes |
Operating System | apple | macos | - | No |
Operating System | linux | linux_kernel | - | No |