CVE-2019-13608 - XML External Entity (XXE) Processing Vulnerability in Citrix StoreFront Server

Related Vulnerabilities: CVE-2019-13608  

Description of Problem

An XML External Entity (XXE) processing vulnerability has been identified in Citrix StoreFront Server that could allow an unauthenticated attacker to retrieve potentially sensitive information from the server.

This vulnerability has been assigned the following CVE number:

• CVE-2019-13608: XML External Entity (XXE) Processing Vulnerability in Citrix StoreFront Server.

This vulnerability affects the following Citrix StoreFront Server versions:

• Citrix StoreFront Server  earlier than 1903

• Citrix StoreFront Server 7.15 LTSR earlier than CU4 (3.12.4000)

• Citrix StoreFront Server 7.6 LTSR earlier than CU8 (3.0.8000)

Mitigating Factors

Considerations for StoreFront front ended by NetScaler as documented here: https://docs.citrix.com/en-us/netscaler-gateway/12/integrate-with-storefront.html

In configurations with the NetScaler Gateway integration a client that is outside the trusted network must authenticate in order to able to execute the attack against Storefront.This configuration makes this an authenticated attack, rather than an unauthenticated one, adding an additional layer of defense.

Clients within the trusted network will be able to execute the attack against the StoreFront as documented.

What Customers Should Do

The XXE vulnerability has been addressed in the following Citrix StoreFront Server versions:

• StoreFront 1903

• StoreFront 7.15 LTSR CU4 (3.12.4000)

• StoreFront 7.6 LTSR CU8 (3.0.8000)

Citrix strongly recommends that customers upgrade their Citrix StoreFront Server deployments to one of these versions or newer. These updates can be obtained from the following location:

https://www.citrix.com/downloads/storefront/

Acknowledgements

Citrix thanks Vahagn Vardanyan for working with us to protect Citrix customers.

What Citrix Is Doing

Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/.

Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.html

Reporting Security Vulnerabilities

Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For guidance on how to report security-related issues to Citrix, please see the following document: CTX081743 – Reporting Security Issues to Citrix

Changelog

Date  Change
20th August 2019 Initial Publishing
28th August 2019 Added "Mitigating Factors" section