This message was deleted.
# citrix-netscaler
s
This message was deleted.
๐Ÿ˜„ 1
๐Ÿ˜‘ 1
๐Ÿ™ 4
๐Ÿ’ฉ 2
n
Dang, right after we upgraded 1 of our sites to the latest (at the time) 13.0 builds.
I am a little bit unclear as to the severity of this disclosure, obviously CVSS score of 6.1 is much lower than some of the 9.x+ vulns we've seen in the past, but the CTX article doesn't say much other than it's a cross site scripting exploit. Even searching twitter/security blogs for info doesn't return much. In a perfect world we'd all upgrade our stuff the day disclosures happen but in the real world, it's gonna take us a couple weekends to make it there most likely.
j
We consider the threat as medium, so no rush to go and deploy today. But I would not delay the upgrade longer than necessary. We all know how much time it takes sometimes to get the customers involved and get approval, so you might look at a week delay anyway.
e
I am very interested in some more details regarding pre-requisites for CVE-2023-24488. For example - Does it require that the threat actor be authenticated and logged in to the AAA/Gateway-vserver first.
j
No, you just need the feature enabled and in use. The XSS is probably related to the web interface presented during login attempts.
(At least, thatโ€™s what we know until know as no further details are available)
e
Yep.