
CVE-2023-6588
https://notcve.org/view.php?id=CVE-2023-6588
07 Dec 2023 — Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline. El modo sin conexión siempre está habilitado, incluso si el permiso no lo permite, en la fuente de datos del servidor de Devolutions en Devolutions Workspace 2023.3.2.0 y versiones anteriores. Esto permite que un atacante con acceso a la aplicación Workspace acce... • https://devolutions.net/security/advisories/DEVO-2023-0022 •

CVE-2023-24486 – Local user access to a system where another user is utilizing a vulnerable version of Citrix Workspace App for Linux to launch published desktops and applications
https://notcve.org/view.php?id=CVE-2023-24486
10 Jul 2023 — A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. • https://support.citrix.com/article/CTX477618/citrix-workspace-app-for-linux-security-bulletin-for-cve202324486 • CWE-284: Improper Access Control •

CVE-2023-2257
https://notcve.org/view.php?id=CVE-2023-2257
24 Apr 2023 — Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This vulnerability occurs only if "Force Login" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business sp... • https://devolutions.net/security/advisories/DEVO-2023-0011 • CWE-863: Incorrect Authorization •

CVE-2023-24484 – A malicious user can cause log files to be written to a directory that they do not have permission to write to.
https://notcve.org/view.php?id=CVE-2023-24484
16 Feb 2023 — A malicious user can cause log files to be written to a directory that they do not have permission to write to. • https://support.citrix.com/article/CTX477617/citrix-workspace-app-for-windows-security-bulletin-for-cve202324484-cve202324485 • CWE-284: Improper Access Control •

CVE-2023-24485 – Privilege Escalation on the system running a vulnerable version of Citrix Workspace app for Windows
https://notcve.org/view.php?id=CVE-2023-24485
16 Feb 2023 — Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. • https://support.citrix.com/article/CTX477617/citrix-workspace-app-for-windows-security-bulletin-for-cve202324484-cve202324485 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •

CVE-2022-47412 – ONLYOFFICE Workspace Search Stored XSS
https://notcve.org/view.php?id=CVE-2022-47412
07 Feb 2023 — Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition. • https://github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.md#733 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-22907
https://notcve.org/view.php?id=CVE-2021-22907
27 May 2021 — An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4. Se presenta una vulnerabilidad de control de acceso inapropiado en la aplicación Citrix Workspace para Windows que potencialmente permite una escalada de privilegios en CR versiones anteriores a 2105 y 1912 LTSR versiones anteriores a CU4 • https://support.citrix.com/article/CTX307794 • CWE-284: Improper Access Control •

CVE-2019-11634 – Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2019-11634
22 May 2019 — Citrix Workspace App before 1904 for Windows has Incorrect Access Control. La aplicación Citrix Workspace antes de 1904 para Windows tiene un control de acceso incorrecto. Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. • https://support.citrix.com/article/CTX251986 • CWE-284: Improper Access Control •