What is Citrix Content Collaboration?
Citrix Content Collaboration is a security-focused collaboration, content sharing and synchronization service from Citrix for the enterprise.
What is the Attack?
CVE-2023-24489 is a directory traversal vulnerability that affects Citrix Systems ShareFile StorageZones Controller prior to 5.11.24.
The vulnerability is due to improper validation of user input in the ProcessRawPostedFile function. A remote, unauthenticated attacker could exploit this vulnerability by sending crafted requests to the target server. Successful exploitation could allow an attacker to save files to an arbitrary file path under the web root directory, which could lead to the execution of arbitrary code.
The vulnerability has a CVSS score of 9.1 and is rated critical by Citrix.
Why is this Significant?
This is significant because CISA added CVE-2023-24489 to the Known Exploited Vulnerabilities catalog on August 16, 2023, indicating that an attempted or successful exploitation has been observed. Therefore, FortiGuard Labs advises all users of the service to apply the patch as soon as possible.
What is the Vendor Solution?
Citrix released relevant updates in June, 2023.
What FortiGuard Coverage is available?
FortiGuard Labs has an IPS signature “C Citrix.ShareFile.SZC.ProcessRawPostedFile.Directory.Traversal” in place for CVE-2023-24489.
More Stories
dnf-4.23.0-1.fc40.1
FEDORA-2025-21c36b3aa5 Packages in this update: dnf-4.23.0-1.fc40.1 Update description: This releases preserves enablement state of dnf-automatic.timer when upgrading to Fedora 41....
podman-tui-1.5.0-2.el9
FEDORA-EPEL-2025-7c57e75cbc Packages in this update: podman-tui-1.5.0-2.el9 Update description: release v1.5.0 Read More
prometheus-podman-exporter-1.16.0-1.fc42
FEDORA-2025-12ac4e9cfd Packages in this update: prometheus-podman-exporter-1.16.0-1.fc42 Update description: release v1.16.0 Read More
prometheus-podman-exporter-1.16.0-1.fc41
FEDORA-2025-b0915f0a19 Packages in this update: prometheus-podman-exporter-1.16.0-1.fc41 Update description: release v1.16.0 Read More
prometheus-podman-exporter-1.16.0-1.el9
FEDORA-EPEL-2025-6653a27cfd Packages in this update: prometheus-podman-exporter-1.16.0-1.el9 Update description: release 1.16.0 Read More
jupyterlab-4.4.0-1.fc40 python-notebook-7.4.0-1.fc40
FEDORA-2025-5ea8e7d744 Packages in this update: jupyterlab-4.4.0-1.fc40 python-notebook-7.4.0-1.fc40 Update description: New jupyterlab and notebook Read More