CVE-2021-22914
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of Citrix Cloud Connector that were installed by passing secure client parameters for installation via the command line. The issue does not affect Citrix Cloud Connector if it was installed using the interactive installer or where a parameter file was used with the command-line installer.
Citrix Cloud Connector versiones anteriores a 6.31.0.62192, sufre de almacenamiento no seguro de información confidencial debido a que la información confidencial es almacenada en los archivos de registro de instalación de Citrix Cloud Connector. Esta información podría ser usada por un actor malicioso para acceder a un entorno de Citrix Cloud. Este problema afecta a todas las versiones de Citrix Cloud Connector que fueron instaladas pasando parámetros de cliente seguro para la instalación por medio de la línea de comandos. El problema no afecta a Citrix Cloud Connector si se instaló mediante el instalador interactivo o si se usó un archivo de parámetros con el instalador de línea de comandos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-06 CVE Reserved
- 2021-06-16 CVE Published
- 2024-03-01 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-922: Insecure Storage of Sensitive Information
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.citrix.com/article/CTX316690 | 2021-06-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Cloud Connector Search vendor "Citrix" for product "Cloud Connector" | < 6.31.0.62192 Search vendor "Citrix" for product "Cloud Connector" and version " < 6.31.0.62192" | - |
Affected
|