PT-2020-11934 · Citrix · Citrix Gateway+1

Micha Borrmann

·

Published

2020-03-06

·

Updated

2024-08-04

·

CVE-2020-10112

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Citrix Gateway versions 11.1 through 12.1
Description The issue allows Cache Poisoning. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default. Citrix disputes this as not a vulnerability.
Recommendations For Citrix Gateway versions 11.1 through 12.1, consider disabling the caching feature for static content served under certain URL paths as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2020-10112

Affected Products

Citrix Adc
Citrix Gateway