We've observed a series of distinct GET requests hitting our load balancer with a common format, exemplified as "https://aaa...[repeats hundreds of times]...aaa/oauth/idp/.well-known/openid-configuration". These requests consistently return a status code of 302, and originate from several different datacenters. In light of this, we're concerned that this may be an attempt to exploit the Citrix bleed vulnerability, particularly given the similarities with a widely shared post[1] that describes a similar URL as a gateway for potential exploitation.
We have a few questions and would appreciate any insights or guidance:
Any insights or recommendations from the community would be greatly appreciated. Thank you in advance for your assistance.