CVE-2020-10110

Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request or a response. The "Age" header provides the age of the cached response in seconds. Both headers are commonly used for proxy cache and the information is not sensitive
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:citrix:gateway_firmware:11.1:*:*:*:*:*:*:*
cpe:2.3:o:citrix:gateway_firmware:12.0:*:*:*:*:*:*:*
cpe:2.3:o:citrix:gateway_firmware:12.1:*:*:*:*:*:*:*

History

21 Nov 2024, 04:54

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/156656/Citrix-Gateway-11.1-12.0-12.1-Information-Disclosure.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/156656/Citrix-Gateway-11.1-12.0-12.1-Information-Disclosure.html - Exploit, Third Party Advisory, VDB Entry
References () https://seclists.org/fulldisclosure/2020/Mar/7 - Exploit, Mailing List, Third Party Advisory () https://seclists.org/fulldisclosure/2020/Mar/7 - Exploit, Mailing List, Third Party Advisory
References () https://support.citrix.com/search - Vendor Advisory () https://support.citrix.com/search - Vendor Advisory

07 Nov 2023, 03:14

Type Values Removed Values Added
Summary ** DISPUTED ** Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request or a response. The "Age" header provides the age of the cached response in seconds. Both headers are commonly used for proxy cache and the information is not sensitive. Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request or a response. The "Age" header provides the age of the cached response in seconds. Both headers are commonly used for proxy cache and the information is not sensitive

Information

Published : 2020-03-06 21:15

Updated : 2024-11-21 04:54


NVD link : CVE-2020-10110

Mitre link : CVE-2020-10110

CVE.ORG link : CVE-2020-10110


JSON object : View

Products Affected

citrix

  • gateway_firmware