PT-2020-11934 · Citrix · Citrix Gateway+1
Micha Borrmann
·
Published
2020-03-06
·
Updated
2024-08-04
·
CVE-2020-10112
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Citrix Gateway versions 11.1 through 12.1
Description
The issue allows Cache Poisoning. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default. Citrix disputes this as not a vulnerability.
Recommendations
For Citrix Gateway versions 11.1 through 12.1, consider disabling the caching feature for static content served under certain URL paths as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Adc
Citrix Gateway