PT-2021-15271 · Citrix · Citrix Cloud Connector

Published

2021-06-16

·

Updated

2021-06-24

·

CVE-2021-22914

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Citrix Cloud Connector versions prior to 6.31.0.62192
Description The issue is related to the insecure storage of sensitive information in the Citrix Cloud Connector installation log files. This sensitive information could be used by a malicious actor to access a Citrix Cloud environment. The problem specifically affects versions of Citrix Cloud Connector that were installed by passing secure client parameters via the command line.
Recommendations For versions prior to 6.31.0.62192, update to version 6.31.0.62192 or later to resolve the issue. As a temporary workaround, consider restricting access to the installation log files to minimize the risk of exploitation.

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22914

Affected Products

Citrix Cloud Connector