Okta fixes Sign-On Policy Bypass Flaw

Okta fixes Sign-On Policy Bypass Flaw


Okta has patched a critical security vulnerability affecting its classic product that could allow attackers to bypass application-specific sign-on policies.

The vulnerability was initially identified on September 27, 2024, and after an internal investigation, determined that it had originated from a software update rolled out on July 17, 2024 afrecting Okta Classic and impacted organizations that had configured application-specific sign-on policies, especially those that relied on device-type restrictions or additional conditions outside the platform’s Global Session Policy

An attacker would need to meet several conditions to carry out a successful attack. First, the attacker needed access to valid credentials—either through phishing, credential stuffing, or brute-force attacks. Second, the organization had to be using application-specific sign-on policies.

Advertisements

Also, the attacker had to be using a device or script that Okta evaluated as an “unknown” user-agent type, which might evade detection by standard device-type restrictions. Once these conditions were met, the attacker might have bypassed sign-on policies that typically require additional layers of authentication or device verification.

Okta has provided specific search recommendations

  • Look for unexpected successful authentication events where the device type was flagged as “unknown.”
  • Search for unsuccessful authentication attempts, which could indicate credential-based attacks preceding a successful login.
  • Organizations were encouraged to monitor for deviations in user behavior, such as unfamiliar IP addresses, geolocations, or access times that could signal unauthorized activity

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.