Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.
2022-03-23T20:15:10.757
2024-11-21T06:39:53.480
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | okta | advanced_server_access | < 1.58.0 | Yes |
| Operating System | apple | macos | - | No |
| Operating System | linux | linux_kernel | - | No |