GHSA-5hj5-f578-54jwMediumCVSS 6.0
The Okta Access Gateway does not apply its Lua directive restriction to the application-level...
🔗 CVE IDs covered (1)
📋 Description
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.