In a new security advisory, Okta has revealed that its system had a vulnerability that allowed people to log into an account without having to provide the correct password. Okta bypassed password authentication if the account had a username that had 52 or more characters. Further, its system had to detect a “stored cache key” of a previous successful authentication, which means the account’s owner had to have previous history of logging in using that browser. It also didn’t affect organizations that require multi-factor authentication, according to the notice the company sent to its users.
Still, a 52-character username is easier to guess than a random password — it could be as simple as a person’s email address that has their full name along with their organization’s website domain. The company has admitted that the vulnerability was introduced as part of a standard update that went out on July 23, 2024 and that it only discovered (and fixed) the issue on October 30. It’s now advising customers who meet all of the vulnerability’s conditions to check their access log over the past few months.
Okta provides software that makes it easy for companies to add authentication services to their application. For organizations with multiple apps, it gives users access to a single, unified log-in so they don’t have to verify their identities for each application. The company didn’t say whether it’s aware of anybody who’s been affected by this specific issue, but it promised to “communicate more rapidly with customers” in the past after the threat group Lapsus$ accessed a couple of users’ accounts.
Trending Products
LG UltraGear QHD 27-Inch Gaming Monitor 27GL83A-B – IPS 1ms (GtG), with HDR 10 Compatibility, NVIDIA G-SYNC, and AMD FreeSync, 144Hz, Black
LG 24MP60G-B 24″ Full HD (1920 x 1080) IPS Monitor with AMD FreeSync and 1ms MBR Response Time, and 3-Side Virtually Borderless Design – Black
Acer Nitro 27″ WQHD 2560 x 1440 PC Gaming IPS Monitor | AMD FreeSync Premium Up to 180Hz Refresh 0.5ms DCI-P3 95% 1 Display Port 1.2 & 2 HDMI 2.0 XV271U M3bmiiprx,Black
Logitech MK345 Wireless Keyboard and Mouse Combo with Palm Rest, 2.4 GHz USB Receiver, Compatible with PC, Laptop, Black
Motorola MG7550 – Modem with Built in WiFi | Approved for Comcast Xfinity, Cox | For Plans Up to 300 Mbps | DOCSIS 3.0 + AC1900 WiFi Router | Power Boost Enabled
HP 230 Wireless Mouse and Keyboard Combo – 2.4GHz Wireless Connection – Long Battery Life – Durable & Low-Noise Design – Windows & Mac OS – Adjustable 1600 DPI – Numeric Keypad (18H24AA#ABA)
ASUS TUF Gaming GT502 ATX Full Tower PC Case, Tempered Glass, Tool-free Side Panel, Modular Design, ARGB Hub, 2- way Graphic Card Mounting Orientation Compatible, 360mm and 280mm Radiator compatible
Lenovo 15.6″ FHD Laptop, Intel Pentium N6000 Quad-core Processor, 16GB Memory, 1TB SSD Storage, Ethernet Port, HDMI, USB-C, WiFi & Bluetooth, Windows 11 Home, WOWPC USB Bundle
Thermaltake View 200 TG ARGB Motherboard Sync ATX Tempered Glass Mid Tower Computer Case with 3x120mm Front ARGB Fan, CA-1X3-00M1WN-00
