Description
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://support.citrix.com/article/CTX297155 |
|
History
No history.
Subscriptions
Citrix
Subscribe
Application Delivery Controller
Subscribe
Application Delivery Controller Firmware
Subscribe
Gateway
Subscribe
Mpx\/sdx 14030 Fips
Subscribe
Mpx\/sdx 14060 Fips
Subscribe
Mpx\/sdx 14080 Fips
Subscribe
Mpx 15030-50g Fips
Subscribe
Mpx 15040-50g Fips
Subscribe
Mpx 15060-50g Fips
Subscribe
Mpx 15080-50g Fips
Subscribe
Mpx 15100-50g Fips
Subscribe
Mpx 15120-50g Fips
Subscribe
Mpx 8905 Fips
Subscribe
Mpx 8910 Fips
Subscribe
Mpx 8920 Fips
Subscribe
Netscaler Gateway
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T09:56:28.314Z
Reserved: 2020-01-28T00:00:00.000Z
Link: CVE-2020-8300
No data.
Status : Modified
Published: 2021-06-16T14:15:08.440
Modified: 2024-11-21T05:38:41.320
Link: CVE-2020-8300
No data.
OpenCVE Enrichment
No data.
Weaknesses