Okta, an identity and access management software provider, officially announced that on October 30, 2024, a vulnerability in AD/LDAP DelAuth's cache key generation was discovered internally. The Bcrypt algorithm is used to generate cache keys, where we hash the combined string of userId + username + password. Under certain conditions, this can allow users to authenticate by simply providing a stored cache key of a previously successfully authenticated username.
The premise of this vulnerability is that each time a cache key is generated for a user, the username must be equal to or longer than 52 characters. The affected products and versions are Okta AD/LDAP DelAuth as of July 23, 2024, and the vulnerability was resolved in Okta's production environment on October 30, 2024.