CVE-2024-0981

Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these credentials within Okta Personal. A fix was implemented to properly escape these fields, addressing the vulnerability. Importantly, if Okta Personal is not added to the plugin to enable multi-account view, the Workforce Identity Cloud plugin is not affected by this issue. The vulnerability is fixed in Okta Browser Plugin version 6.32.0 for Chrome/Edge/Safari/Firefox.
Configurations

No configuration.

History

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Las versiones 6.5.0 a 6.31.0 de Okta Browser Plugin (Chrome/Edge/Firefox/Safari) son vulnerables a Cross Site Scripting. Este problema ocurre cuando el complemento solicita al usuario que guarde estas credenciales en Okta Personal. Se implementó una solución para escapar correctamente de estos campos, solucionando la vulnerabilidad. Es importante destacar que si Okta Personal no se agrega al complemento para habilitar la vista de múltiples cuentas, el complemento Workforce Identity Cloud no se ve afectado por este problema. La vulnerabilidad se solucionó en Okta Browser Plugin versión 6.32.0 para Chrome/Edge/Safari/Firefox.

23 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-23 21:15

Updated : 2024-07-24 12:55


NVD link : CVE-2024-0981

Mitre link : CVE-2024-0981

CVE.ORG link : CVE-2024-0981


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')