Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Okta Access Gateway, specifically affecting its advanced mode datastore configuration. The issue involves the improper handling of security assertion data, which could allow for unauthorized database manipulation. The main concern is confirming relevance and exposure within your Okta Access Gateway deployments.
- Unsanitized data can lead to database compromise.
- It's an edge security product, public-facing by design.
- Confirm if your advanced datastore configuration is affected.
Attack Path
How an attacker could exploit the issue
An attacker with limited access could target the Okta Access Gateway by sending crafted SAML assertions. When the gateway is configured in advanced mode and uses the datastore feature, it fails to properly handle these assertions. This allows the attacker to inject malicious SQL commands, potentially leading to significant data compromise and system control.
- Requires low-privileged access.
- Unsanitized SAML assertions trigger vulnerability.
- Leads to SQL injection and data compromise.
Live Threat
Current exploitation, exposure, and threat context
When Okta Access Gateway is configured in advanced mode with datastore integration, it may allow an attacker to execute arbitrary SQL commands against the backend database by sending a crafted SAML assertion. This could expose sensitive information stored within the database or disrupt service operations.
- Database information may be exposed.
- Unsanitized SAML assertions could be exploited.
- Unauthorized data access or service disruption.
Operational Fix
Recommended remediation, mitigation, and detection steps
Okta Access Gateway's SQL injection vulnerability likely falls under the purview of infrastructure or platform teams managing the gateway, with potential involvement from network and security teams for exposure assessment and vendor management for Okta coordination. The immediate priority is to confirm the deployment's reachability and business criticality, identify the system owner, and plan remediation with Okta based on assessed risk.
- Own by infrastructure or platform teams.
- Verify external reachability and business impact.
- Coordinate with Okta for patch or mitigation.