Collected research
Citrix Bleed: Leaking Session Tokens with CVE-2023-4966
Patch-diffs NetScaler to locate an OpenID endpoint that uses snprintf's would-have-written return value as the response length. An oversized Host header makes the server over-read adjacent memory and repeatedly disclose active NetScaler session cookies.
Record
- Published by
- slcyber.io
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of slcyber.io, first published at the original source. Preserved copies are kept so the citation survives its host.