First published: Fri Sep 18 2020(Updated: )
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix StoreFront | <2006 | |
Citrix StoreFront | >=3.0<3.0.8001 | |
Citrix StoreFront | >=3.12<3.12.5001 | |
Citrix StoreFront | >=1912<1912.0.1000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8200 is classified as a high-severity vulnerability due to its potential for improper authentication and unauthorized file access.
To mitigate CVE-2020-8200, upgrade to Citrix StoreFront Server version 1912.0.1000 or later.
Anyone using Citrix StoreFront Server versions earlier than 1912.0.1000 within the same Microsoft Active Directory domain is at risk.
CVE-2020-8200 allows an attacker authenticated on the same Active Directory domain to read arbitrary files on the Citrix StoreFront server.
CVE-2020-8200 was reported in 2020, highlighting vulnerabilities within older versions of Citrix StoreFront Server.