Okta’s AD/LDAP Authentication Flaw Exposes Passwordless Login Vulnerability
A critical vulnerability was discovered in Okta’s AD/LDAP DelAuth solution, allowing attackers to log in without a password under specific circumstances. The bug, which was introduced through a routine July 23, 2024 update, stems from the use of the Bcrypt algorithm to generate cache keys. The vulnerability exploited when usernames were 52 characters long or … Read more