Jun 29, 2023
URL query parameters are not adequately sanitised before they are placed into an HTTP Location
header. An attacker can exploit this to create a link which, when clicked, redirects the victim to an arbitrary location. Alternatively the attacker can inject newline characters into the Location
header, to prematurely end the HTTP headers and inject an XSS payload into the response body.
An attacker can craft malicious links which, when clicked, either redirect the victim to an attacker controlled website or execute JavaScript in the victim’s browser.
The following versions are affected by this vulnerability:
Citrix Gateway is a network appliance providing multiple functions including remote access VPN services.
Upgrade to the latest version of Citrix Gateway.
Citrix’s official advisory can be found here.
The blog post detailing the steps taken for the discovery of this vulnerability can be found here.
Dylan Pindur - Assetnote Security Research Team
Find out how Assetnote can help you lock down your external attack surface.
Use the lead form below, or alternatively contact us via email by clicking here.