Impact
The Okta Hyperdrive Integration installer records the OAuth client secret in clear text when the secret is passed as an MSI property. The plaintext credential is written to the installer log, the Application Event Log, and the process command line, all of which can be accessed by any authenticated local user on the workstation. The vulnerability allows a local user to obtain an OAuth client secret that can be used to impersonate or compromise the Okta integration, leading to potential unauthorized access to integrated applications. The weakness is a failure to mask sensitive data during logging (CWE‑532).
Affected Systems
Any system running the Okta Hyperdrive Integration Plugin prior to version 1.5.2 is impacted. The vendor recommends upgrading to version 1.5.2 or later to mitigate the risk. Exact affected versions prior to the fix are not enumerated in the advisory.
Risk and Exploitability
The advisory lists a CVSS score of 7.3, indicating high risk to confidentiality. The EPSS score is not available; the risk assessment relies on the CVSS severity. The vulnerability is not part of the CISA KEV catalog, but the attack vector is local and requires an authenticated user with standard workstation access. Therefore, any local user with privilege to run installs or view logs could exploit this flaw. The potential impact includes exposure of OAuth credentials that can lead to unauthorized access to linked services.
OpenCVE Enrichment