First published: Wed Nov 08 2023(Updated: )
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.
Credit: psirt@okta.com
Affected Software | Affected Version | How to fix |
---|---|---|
Okta Ldap Agent | <5.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the LDAP Agent Update service is CVE-2023-0392.
The severity of CVE-2023-0392 is medium with a CVSS score of 6.7.
The LDAP Agent Update service versions prior to 5.18 are affected by CVE-2023-0392.
CVE-2023-0392 could allow arbitrary code execution.
To fix CVE-2023-0392, update the LDAP Agent Update service to version 5.18 or above.