CyberRota Analysis
AI-GeneratedNginx is vulnerable due to a flaw in the Okta Access Gateway, where the Lua directive restriction is not enforced on the application-level custom configuration field, allowing for the execution of injected directives. This could lead to unauthorized command execution, potentially compromising the integrity of the server. Organizations utilizing Okta Access Gateway with Nginx should prioritize this vulnerability to mitigate risks associated with potential exploitation.
Original NVD Description
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.