Two vulnerabilities have been discovered that impact the Citrix Workspace app for HTML5. Refer to below for further details:
The vulnerabilities affect the following supported versions of the Citrix Workspace app for HTML5.
Citrix Workspace app for HTML5 before 2404.1
This bulletin only applies to customer-managed Citrix Workspace app for HTML5. Customers using Citrix-managed cloud services do not need to take any action.
Citrix Workspace app for HTML5 contains the vulnerability mentioned below
CVE ID | Description | Pre-requisites | CWE | CVSS |
CVE-2024-6148 | Bypass of GACS Policy Configuration settings | Global App Configuration service (GACS) configured environment | CWE-276: Incorrect Default Permissions |
CVSS v4.0 Base Score: 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N) |
CVE-2024-6149 | Redirection of users to a vulnerable URL | Authenticated access to the store where the capability to launch the HTML5 session is enabled | CWE-601: URL Redirection to Untrusted Site ('Open Redirect') |
CVSS v4.0 Base Score: 4.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N) |
Citrix strongly recommends that customers upgrade their Citrix Workspace app for HTML5 to the version containing the fixes as soon as possible.
Citrix Workspace app for HTML5 versions that contain the fixes are:
Citrix Workspace app for HTML5 2404.1 and later versions
Customers can upgrade vulnerable version of Citrix Workspace app for HTML5 on StoreFront CR or LTSR Layouts by downloading Citrix Workspace app for HTML5 2404.1 and later versions from https://www.citrix.com/downloads/workspace-app/html5/workspace-app-for-html5-latest.htm and following the instructions mentioned at https://docs.citrix.com/en-us/citrix-workspace-app-for-html5/deploy.html#to-upgrade-citrix-workspace-app-for-html5-on-storefront'
Cloud Software Group thanks Matthias Zöllner of Cyvisory and Mauro Dini for working with us to protect Cloud Software Group customers.
2024-07-09 | Initial Publication |
2024-07-15 | Platform migration |