CVE-2022-1030
Last modified
CVE-2022-1030 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Okta | Advanced Server Access | < 1.58.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1030?
How severe is CVE-2022-1030?
How do I fix CVE-2022-1030?
Are you affected by CVE-2022-1030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
