CyberRota Analysis
AI-GeneratedThe Okta Hyperdrive Agent is vulnerable due to the logging of decoded SAML bearer assertions in a local application log file after successful multi-factor authentication (MFA) completions. This exposure allows any local user with access to the log file to read sensitive authentication credentials, potentially leading to unauthorized access. Organizations using the Okta Hyperdrive Agent should prioritize remediation to mitigate the risk of credential theft.
Original NVD Description
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.