Okta Security Advisory Exploit Found via Long Username Vulnerability
Okta has issued an unusual security advisory update, revealing that under specific circumstances, an attacker could log in by only providing a username with a stored cache key from a previous successful authentication. The vulnerability is related to the Bcrypt algorithm used to generate the cache key for AD/LDAP DelAuth. According to Okta, this exploit … Read more