Skip to content
OktaOKTA-01PIZ3E

Okta Access Gateway Advisory for CVE-2022-3602 and CVE-2022-3786 - Nov 1, 2022

UnratedCVE-2022-3602 · Published Nov 1, 2022

On November 1, 2022 the OpenSSL organization disclosed two high-severity vulnerabilities in version 3.0 and above which are patched in OpenSSL 3.0.7. Okta has investigated the usage of the vulnerabilities and will continue to assess the potential impact to our dependencies and third parties. Okta Access Gateway has been found to use the OpenSSL 3.0 codebase since the release of 2022.10.0. Customers that have not yet updated to 2022.10.0 should refrain from updating to 2022.10.0 which contains OpenSSL 3.0 until an updated version is available. Okta Access Gateway customers who have updated to 2022.10.0 will be provided an updated version 2022.11.0 as soon as possible. Currently estimated to be available on 11/04/2022.

Okta advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Okta advisories

All Okta
Advisory
Okta Advanced Server Access Client CVE-2023-0093 - Feb 22, 2023
UnratedFeb 22, 2023
Okta Active Directory Agent CVE-2022-1697 - Sep 1, 2022
UnratedSep 1, 2022
Okta Advanced Server Access Client CVE-2022-1030 - Mar 21, 2022
UnratedMar 21, 2022
Okta Advanced Server Access Client CVE-2022-24295 - Feb 17, 2022
UnratedFeb 17, 2022
Okta RADIUS Server Agent CVE-2021-45105 - Jan 26, 2022
UnratedJan 26, 2022
Okta On-Prem MFA Agent CVE-2021-45046 - Jan 26, 2022
UnratedJan 26, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.