Security Advisory

CVE-2022-1030

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-03-23 19:46:14
Last updated 2024-08-02 23:47:43
Assigner Okta
CVSS score not scored
State PUBLISHED

Description

Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.