Skip to main content

Okta Releases Security Updates for Access Gateway

Security update addresses the OpenSSL remote code execution and denial-of-service vulnerabilities

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security update addresses the OpenSSL remote code execution and denial-of-service vulnerabilities


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Okta has released a security update to address OpenSSL remote code execution (RCE) and denial-of-service (DoS) vulnerabilities. A remote, unauthenticated attacker could exploit this command injection vulnerability by sending a specially crafted URL and take control of an affected system.


Remediation advice

Affected organisations should read Okta's security advisory and update to Access Gateway version 2022.11.0



CVE Vulnerabilities

Last edited: 7 November 2022 11:59 am