Remediate vulnerabilities for CVE-2021-22927 and CVE-2021-22920
<number of> NetScaler instances are impacted by CVEs, you can see all the instances vulnerable due to CVE-2021-22927 and CVE-2021-22920. To check the details of the instances impacted by these two CVEs, select one or more CVEs and click View Affected Instances.
<number of> NetScaler instances impacted by CVEs window appears. In the following screen capture, you can see the count and details of the NetScaler instances impacted by CVE-2021-22927 and CVE-2021-22920.
Remediate CVE-2021-22927 and CVE-2021-22920
-
Upgrading the vulnerable NetScaler instances to a release and build that has the fix.
-
Applying the required configuration commands using the customizable built-in configuration template in configuration jobs. Follow this step for each vulnerable NetScaler one at a time and include all SAML actions for that NetScaler.
Step 1: Upgrade the vulnerable NetScaler instances
Step 2: Apply configuration commands
<number of> NetScaler instances impacted by CVEs window, select one instance impacted by CVE-2021-22927 and CVE-2021-22920 and click Proceed to configuration job workflow. The workflow includes the following steps.
-
Customizing the configuration.
-
Reviewing the auto-populated impacted instances.
-
Specifying inputs for variables for the job.
-
Reviewing the final config with variable inputs populated.
-
Running the job.
-
For a NetScaler instance impacted by multiple CVEs (such as CVE-2020-8300, CVE-2021-22927, CVE-2021-22920, and CVE-2021-22956): when you select the instance and click Proceed to configuration job workflow, the built-in configuration template does not auto-populate under Select configuration. Drag and drop the appropriate config job template under Security Advisory Template manually to the config job pane on the right side.
-
For multiple NetScaler instances that are impacted by CVE-2021-22956 only: you can run config jobs on all instances at once. For example, you've NetScaler 1, NetScaler 2, and NetScaler 3, and all of them are impacted only by CVE-2021-22956. Select all these instances and click Proceed to configuration job workflow, and the built-in configuration template auto-populates under Select configuration.
-
For multiple NetScaler instances impacted by CVE-2021-22956 and one or more other CVEs (such as CVE-2020-8300, CVE-2021-22927, and CVE-2021-22920), which require remediation to be applied to each NetScaler at a time: when you select these instances and click Proceed to configuration job workflow, an error message appears telling you to run the config job on each NetScaler at a time.
Step 1: Select configuration
| NetScaler 1 | NetScaler 2 |
|---|---|
| Job 1: two SAML actions | Job 2: two SAML actions |
bind patset $saml_action_patset$ “$saml_action_domain1$” multiple times to ensure that the line appears N times for that SAML action. And change the following variable definition names:
-
saml_action_patset: is the config template variable, and it represents the value of the name of the pattern set (patset) for the SAML action. You can specify the real value in step 3 of the config job workflow. See the section Step 3: Specify variable values in this doc. -
saml_action_domain1: is the config template variable, and it represents the domain name for that specific SAML action. You can specify the real value in step 3, of the config job workflow. See the section Step 3: Specify variable values in this doc.
show samlaction.
Step 2: Select the instance
Step 3: Specify variable values
-
saml_action_patset: add a name for the SAML action -
saml_action_domain1: enter a domain in the formathttps://<example1.com>/ -
saml_action_name: enter the same of the SAML action for which you are configuring the job
Step 4: Preview the configuration
Step 5: Run the job
Scenario
-
Upgrade all the three NetScaler instances by following the steps given in the "Upgrade an instance" section in this document.
-
Apply the config patch to one NetScaler at a time, using the configuration job workflow. See the steps given in the "Apply configuration commands" section in this document.
-
SAML action 1 has one domain
-
SAML action 2 has two domains
| NetScaler configuration | Variable definition for patset | Variable definition for SAML action name | Variable definition for domain |
|---|---|---|---|
| SAML action 1 has one domain | saml_action_patset1 | saml_action_name1 | saml_action_domain1 |
| SAML action 2 has two domains | saml_action_patset2 | saml_action_name2 | saml_action_domain2, saml_action_domain3 |