book
Article ID: CTX316690
calendar_today
Updated On:
Description
A vulnerability has been identified in Citrix Cloud Connector that may result in sensitive information being stored in the Citrix Cloud Connector installation log files which, if exploited, could allow access to a customer’s Citrix Cloud environment.
CVE ID
|
Description
|
Vulnerability Type
|
Pre-conditions
|
CVE-2021-22914
|
Sensitive information stored in installation logs
|
CWE-922: Insecure Storage of Sensitive Information
|
Citrix Cloud connector must have been installed by passing parameters to the command line installer.
|
This issue affects all versions of Citrix Cloud Connector which were installed by passing secure client parameters for installation via the command line. The issue does not affect Citrix Cloud Connector if it was installed using the interactive installer or where a parameter file was used with the command-line installer.
Mitigating Factors
As documented at
https://docs.citrix.com/en-us/citrix-cloud/citrix-cloud-resource-locations/citrix-cloud-connector/installation.html, installation log files are saved to the host running Citrix Cloud Connector during installation. If customers have followed Citrix recommendation to use a dedicated machine to run Citrix Cloud Connector, access to the installation logs may therefore be restricted.
Instructions
Impacted customers are recommended to delete any Secure Clients from their Citrix Cloud portal which have previously been used for command line installation. Customers are also recommended to review the installation documentation at
https://docs.citrix.com/en-us/citrix-cloud/citrix-cloud-resource-locations/citrix-cloud-connector/installation.html for any future installation of Citrix Cloud Connector as this information has been recently updated.
Acknowledgements
Citrix would like to thank Patrick van den Born of van den Born IT Consultancy for working with us to protect Citrix customers.