Command Injection Vulnerability in Okta Advanced Server Access Client for Linux and macOS
CVE-2022-1030

8.8HIGH

Key Information:

Vendor

Okta

Vendor
CVE Published:
23 March 2022

What is CVE-2022-1030?

The Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 is susceptible to a command injection vulnerability. This flaw allows an attacker, who possesses knowledge of a valid team name and a target host accessible to the user, to execute arbitrary commands on the local system through a specially crafted URL. This poses significant security risks as it can lead to unauthorized system manipulation and potential data breaches.

Affected Version(s)

Advanced Server Access Client Prior to version 1.58.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.