CVE Vulnerabilities

CVE-2023-6184

Improper Control of Dynamically-Managed Code Resources

Published: Jan 18, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Affected Software

Name Vendor Start Version End Version
Virtual_apps_and_desktops Citrix * 2311 (including)
Virtual_apps_and_desktops Citrix 1912 (including) 1912 (including)
Virtual_apps_and_desktops Citrix 1912-cu1 (including) 1912-cu1 (including)
Virtual_apps_and_desktops Citrix 1912-cu2 (including) 1912-cu2 (including)
Virtual_apps_and_desktops Citrix 1912-cu3 (including) 1912-cu3 (including)
Virtual_apps_and_desktops Citrix 1912-cu4 (including) 1912-cu4 (including)
Virtual_apps_and_desktops Citrix 1912-cu5 (including) 1912-cu5 (including)
Virtual_apps_and_desktops Citrix 1912-cu6 (including) 1912-cu6 (including)
Virtual_apps_and_desktops Citrix 1912-cu7 (including) 1912-cu7 (including)
Virtual_apps_and_desktops Citrix 2203 (including) 2203 (including)
Virtual_apps_and_desktops Citrix 2203-cu1 (including) 2203-cu1 (including)
Virtual_apps_and_desktops Citrix 2203-cu2 (including) 2203-cu2 (including)
Virtual_apps_and_desktops Citrix 2203-cu3 (including) 2203-cu3 (including)

Potential Mitigations

References