First published: Wed Mar 23 2022(Updated: )
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.
Credit: psirt@okta.com psirt@okta.com
Affected Software | Affected Version | How to fix |
---|---|---|
Okta Advanced Server Access | <1.58.0 | |
Apple macOS | ||
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-1030.
The severity of CVE-2022-1030 is critical with a CVSS score of 8.8.
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 is affected by CVE-2022-1030.
An attacker with knowledge of a valid team name for the victim and a valid target host where the user has access can execute command injection via a specially crafted URL.
To fix CVE-2022-1030, update Okta Advanced Server Access Client for Linux and macOS to version 1.58.0 or newer.