Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

Unusual GET Requests and Potential Citrix Bleed Vulnerability

We've observed a series of distinct GET requests hitting our load balancer with a common format, exemplified as "https://aaa...[repeats hundreds of times]...aaa/oauth/idp/.well-known/openid-configuration". These requests consistently return a status code of 302, and originate from several different datacenters. In light of this, we're concerned that this may be an attempt to exploit the Citrix bleed vulnerability, particularly given the similarities with a widely shared post[1] that describes a similar URL as a gateway for potential exploitation.

We have a few questions and would appreciate any insights or guidance:

  1. Are these requests considered normal GCP behavior that we might not be aware of?
  2. Is there any information available regarding the susceptibility of GCP services to the Citrix bleed vulnerability?
  3. How are these specific URLs making their way to our load balancer in the first place?

Any insights or recommendations from the community would be greatly appreciated. Thank you in advance for your assistance.

 

[1] : Citrix Bleed Vulnerability

3 0 183
0 REPLIES 0
Top Labels in this Space
Top Solution Authors