Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j5gq-897m-2rff

Опубликовано: 10 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.4

Описание

Race condition in the Okta Java SDK

Description

In the Okta Java SDK, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response.

Affected product and versions

You may be affected if you meet the following preconditions:

  • Using the Okta Java SDK between versions 11.0.0 and 20.0.0, and
  • Implementing a multithreaded application with the ApiClient class where the response status code is used in access control flows

Resolution

Upgrade Okta/okta-sdk-java to versions 21.0.0 or greater.

Пакеты

Наименование

com.okta.sdk:okta-sdk-root

maven
Затронутые версииВерсия исправления

>= 11.0.0, <= 20.0.0

20.0.1

EPSS

Процентиль: 15%
0.00048
Низкий

8.4 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.4
nvd
около 2 месяцев назад

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.

EPSS

Процентиль: 15%
0.00048
Низкий

8.4 High

CVSS3

Дефекты

CWE-362