GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 10-Jul-2025 02:27:51 JSTKevin BeaumontKevin Beaumont
    in reply to

    I believe Citrix may have made a mistake in the patching instructions for CitrixBleed2 aka CVE-2025-5777.

    They say to do the instructions on the left, but they appear to have missed other session types (e.g. AAA) which have session cookies that can be stolen and replayed with CitrixBleed2. On the right is the CitrixBleed1 instructions.

    The net impact is, if you patched but a threat actor already took system memory, they can still reuse prior sessions.

    In conversationabout a year ago from cyberplace.socialpermalink

    Attachments


    1. https://cyberplace.social/system/media_attachments/files/114/824/439/237/364/960/original/2cceb243f6def81c.png

    2. https://cyberplace.social/system/media_attachments/files/114/824/445/741/417/263/original/6b5bf99f292f749b.png
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.