MikeStreetz (0)

Last Login: July 21, 2023
Assessments
0
Score
0

MikeStreetz's Latest (2) Contributions

Sort by:
Filter by:
1

now there’s this (https://bishopfox.com/blog/citrix-adc-gateway-rce-cve-2023-3519) too, which suggests that the SAML thing is something else that got patched, because they exploited something they think is cve-2023-3519 without needing SAML enabled at all.

1

If this is a buffer overflow in SAML, wouldn’t you essentially need to be the IDP to pull this off? How else are you able to send SAML Assertions that the netscaler wouldn’t otherwise drop?