CVE-2023-0093
Last modified
CVE-2023-0093 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. EPSS estimates a 1.10% chance of exploitation in the next 30 days.
Description
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. To exploit this issue, an attacker would need to phish the user to enter an attacker controlled server URL during enrollment.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Okta | Advanced Server Access | >= 1.13.1, < 1.68.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-0093?
How severe is CVE-2023-0093?
How do I fix CVE-2023-0093?
Are you affected by CVE-2023-0093?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
