<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009VfXPUCA3Okta Identity EngineAccess GatewayAnswered2025-03-06T09:00:44.000Z2023-07-25T13:32:37.000Z2023-07-26T22:04:57.000Z

37raf (37raf) asked a question.

Does the Okta on premise servers have exposure to the recently disclosed OpenSSH CVE-2023-38408 vulnerability?

sh-agent is a program to hold private keys used for public key

authentication. Through use of environment variables the agent can

be located and automatically used for authentication when logging in

to other machines using ssh(1). ... Connections to ssh-agent may be

forwarded from further remote hosts using the -A option to ssh(1)

(but see the caveats documented therein), avoiding the need for

authentication data to be stored on other machines."

(https://man.openbsd.org/ssh-agent.1)

 

"Agent forwarding should be enabled with caution. Users with the

ability to bypass file permissions on the remote host ... can access

the local agent through the forwarded connection. ... A safer

alternative may be to use a jump host (see -J)."

(https://man.openbsd.org/ssh.1)

 


  • paul.stiniguta (Okta, Inc.)

    Hello @37raf (37raf)​ Thank you for reacting out to our Community!

     

    I was unable ro find any information on this matter, we recommend to open a case with Support and have this matter investigated and to provide you with the required information.

     

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
This question is closed.
Loading
Does the Okta on premise servers have exposure to the recently disclosed OpenSSH CVE-2023-38408 vulnerability?