VYPR

Okta Verify

by Okta

CVEs (2)

  • CVE-2024-10327HigOct 24, 2024
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the…

  • CVE-2024-9191HigNov 1, 2024
    risk 0.46cvss 7.1epss 0.00

    The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnerability was discovered…