OktaOKTA-1QP0LXS
Okta Advanced Server Access Client CVE-2022-1030 - Mar 21, 2022
UnratedCVE-2022-1030 · Published Mar 21, 2022
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 12022 | Okta Access Gateway Advisory for CVE-2022-3602 and CVE-2022-3786 - Nov 1, 2022 | Unrated | No fix yet |
| Sep 12022 | Okta Active Directory Agent CVE-2022-1697 - Sep 1, 2022 | Unrated | No fix yet |
| Feb 172022 | Okta Advanced Server Access Client CVE-2022-24295 - Feb 17, 2022 | Unrated | No fix yet |
| Jan 262022 | Okta RADIUS Server Agent CVE-2021-45105 - Jan 26, 2022 | Unrated | No fix yet |
| Jan 262022 | Okta On-Prem MFA Agent CVE-2021-45046 - Jan 26, 2022 | Unrated | No fix yet |
| Jan 262022 | Okta RADIUS Server Agent CVE-2021-45046 - Jan 26, 2022 | Unrated | No fix yet |