
CVE-2023-6588
https://notcve.org/view.php?id=CVE-2023-6588
07 Dec 2023 — Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline. El modo sin conexión siempre está habilitado, incluso si el permiso no lo permite, en la fuente de datos del servidor de Devolutions en Devolutions Workspace 2023.3.2.0 y versiones anteriores. Esto permite que un atacante con acceso a la aplicación Workspace acce... • https://devolutions.net/security/advisories/DEVO-2023-0022 •

CVE-2023-24486 – Local user access to a system where another user is utilizing a vulnerable version of Citrix Workspace App for Linux to launch published desktops and applications
https://notcve.org/view.php?id=CVE-2023-24486
10 Jul 2023 — A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. • https://support.citrix.com/article/CTX477618/citrix-workspace-app-for-linux-security-bulletin-for-cve202324486 • CWE-284: Improper Access Control •

CVE-2023-2257
https://notcve.org/view.php?id=CVE-2023-2257
24 Apr 2023 — Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This vulnerability occurs only if "Force Login" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business sp... • https://devolutions.net/security/advisories/DEVO-2023-0011 • CWE-863: Incorrect Authorization •

CVE-2023-24484 – A malicious user can cause log files to be written to a directory that they do not have permission to write to.
https://notcve.org/view.php?id=CVE-2023-24484
16 Feb 2023 — A malicious user can cause log files to be written to a directory that they do not have permission to write to. • https://support.citrix.com/article/CTX477617/citrix-workspace-app-for-windows-security-bulletin-for-cve202324484-cve202324485 • CWE-284: Improper Access Control •

CVE-2023-24485 – Privilege Escalation on the system running a vulnerable version of Citrix Workspace app for Windows
https://notcve.org/view.php?id=CVE-2023-24485
16 Feb 2023 — Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. • https://support.citrix.com/article/CTX477617/citrix-workspace-app-for-windows-security-bulletin-for-cve202324484-cve202324485 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •

CVE-2022-47412 – ONLYOFFICE Workspace Search Stored XSS
https://notcve.org/view.php?id=CVE-2022-47412
07 Feb 2023 — Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition. • https://github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.md#733 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-21825
https://notcve.org/view.php?id=CVE-2022-21825
09 Feb 2022 — An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. Se presenta una vulnerabilidad de control de acceso inapropiado en Citrix Workspace App for Linux 2012 - 2111 con App Protection instalado que puede permitir a un atacante llevar a cabo una escalada de privilegios local • https://support.citrix.com/article/CTX338435 • CWE-284: Improper Access Control •

CVE-2021-22907
https://notcve.org/view.php?id=CVE-2021-22907
27 May 2021 — An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4. Se presenta una vulnerabilidad de control de acceso inapropiado en la aplicación Citrix Workspace para Windows que potencialmente permite una escalada de privilegios en CR versiones anteriores a 2105 y 1912 LTSR versiones anteriores a CU4 • https://support.citrix.com/article/CTX307794 • CWE-284: Improper Access Control •

CVE-2020-8207
https://notcve.org/view.php?id=CVE-2020-8207
24 Jul 2020 — Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running. Un control de acceso inapropiado en la aplicación Citrix Workspace para Windows versiones 1912 CU1 y 2006.1, causa una escalada de privilegios y una ejecución del código cuando el servicio de actualización automática es ejecutado • https://support.citrix.com/article/CTX277662 • CWE-284: Improper Access Control CWE-287: Improper Authentication •

CVE-2019-11634 – Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2019-11634
22 May 2019 — Citrix Workspace App before 1904 for Windows has Incorrect Access Control. La aplicación Citrix Workspace antes de 1904 para Windows tiene un control de acceso incorrecto. Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. • https://support.citrix.com/article/CTX251986 • CWE-284: Improper Access Control •