Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. To exploit this issue, an attacker would need to phish the user to enter an attacker controlled server URL during enrollment.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Okta
Published: 2023-03-06T00:00:00
Updated: 2024-08-02T05:02:43.461Z
Reserved: 2023-01-05T00:00:00
Link: CVE-2023-0093
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-06T21:15:10.933
Modified: 2024-11-21T07:36:32.343
Link: CVE-2023-0093
Redhat
No data.