Citrix ADC and Citrix Gateway are affected by CVE-2023-24488, an input-sanitization flaw in which URL query parameters are insufficiently sanitized before being placed in an HTTP Location header. An attacker can craft a malicious URL that redirects a user to an attacker-controlled site or uses newline characters to terminate the header and inject a cross-site-scripting payload into the response body.
The issue affects designated releases in the 13.1, 13.0, and 12.1 branches, including 12.1-FIPS and 12.1-NDcPP editions. Organizations using affected Citrix Gateway or ADC appliances should identify exposed versions and upgrade to Citrix’s current fixed release to prevent phishing, redirection, and client-side script-injection attacks.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed that Citrix Gateway's unauthenticated `/oauth/idp/logout` endpoint accepts a `post_logout_redirect_uri` value that can produce open redirects and CRLF-injection reflected XSS, even when OAuth is not configured. They estimated roughly 50,000 Internet-accessible instances and found more than half of 100 scanned systems were unpatched.
Citrix ADC and Citrix Gateway were documented as vulnerable to inadequate sanitization of URL query parameters inserted into HTTP Location headers (CVE-2023-24488). Crafted links could redirect users to attacker-controlled sites or use header injection to deliver XSS payloads; Citrix identified fixed versions and recommended upgrading.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourceblog.assetnote.io
Open sourcesupport.citrix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.