Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by this vulnerability if the following preconditions are met: Local server running OPP agent with versions >=2.2.1 and <= 2.3.0, and User account has had an administrator-initiated password reset while using the affected versions.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
Okta On-Premises Provisioning Agent 日志信息泄露漏洞
Vulnerability Description
Okta On-Premises Provisioning Agent是美国Okta公司的一个在本地环境中实现Otka用户帐户的自动化创建、更新和删除的软件。 Okta On-Premises Provisioning Agent 2.3.0及之前版本存在日志信息泄露漏洞,该漏洞源于密码重置期间记录用户数据,可能导致个人信息和临时密码泄露。
CVSS Information
N/A
Vulnerability Type
N/A