Description of Problem
A vulnerability has been identified in Citrix Cloud Connector that may result in sensitive information being stored in the Citrix Cloud Connector installation log files which, if exploited, could allow access to a customer’s Citrix Cloud environment.
CVE ID | Description | Vulnerability Type | Pre-conditions |
CVE-2021-22914 | Sensitive information stored in installation logs | CWE-922: Insecure Storage of Sensitive Information | Citrix Cloud connector must have been installed by passing parameters to the command line installer. |
This issue affects all versions of Citrix Cloud Connector which were installed by passing secure client parameters for installation via the command line. The issue does not affect Citrix Cloud Connector if it was installed using the interactive installer or where a parameter file was used with the command-line installer.