Impact
The Okta Hyperdrive Agent logs the decoded SAML bearer assertion to a local file each time multi‑factor authentication succeeds. Because the assertion contains a live authentication credential, any local user who can read the log file can obtain that credential. This vulnerability falls under improper leakage of sensitive information.
Affected Systems
Okta Hyperdrive Agent is affected. The advisory recommends upgrading to version 1.5.2 or higher. No other product variations or operating systems are mentioned.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is local: an attacker must have read access to the agent log file. Once the log is accessed, the attacker can extract the bearer assertion and impersonate the authenticated user.
OpenCVE Enrichment