Remediate vulnerabilities for CVE-2020-8300
<number of> NetScaler instances are impacted by CVEs, you can see all the instances vulnerable due to this specific CVE. To check the details of the CVE-2020-8300 impacted instances, select CVE-2020-8300 and click View Affected Instances.
<number of> NetScaler instances impacted by CVEs window appears. Here you see the count and details of the NetScaler instances impacted by CVE-2020-8300.
Remediate CVE-2020-8300
-
Upgrading the vulnerable NetScaler instances to a release and build that has the fix.
-
Applying the required configuration commands using the customizable built-in configuration template in configuration jobs. Follow this step for each vulnerable NetScaler one at a time and include all SAML actions and SAML profiles for that NetScaler.
Step 1: Upgrade the vulnerable NetScaler instances
Step 2: Apply configuration commands
<number of> NetScaler instances impacted by CVEs window, select one instance impacted by CVE-2020-8300 and click Proceed to configuration job workflow. The workflow includes the following steps.
-
Customizing the configuration.
-
Reviewing the auto-populated impacted instances.
-
Specifying inputs for variables for the job.
-
Reviewing the final config with variable inputs populated.
-
Running the job.
-
For a NetScaler instance impacted by multiple CVEs (such as CVE-2020-8300, CVE-2021-22927, CVE-2021-22920, and CVE-2021-22956): when you select the instance and click Proceed to configuration job workflow, the built-in configuration template does not auto-populate under Select configuration. Drag and drop the appropriate config job template under Security Advisory Template manually to the config job pane on the right side.
-
For multiple NetScaler instances that are impacted by CVE-2021-22956 only: you can run config jobs on all instances at once. For example, you've NetScaler 1, NetScaler 2, and NetScaler 3, and all of them are impacted only by CVE-2021-22956. Select all these instances and click Proceed to configuration job workflow, and the built-in configuration template auto-populates under Select configuration.
-
For multiple NetScaler instances impacted by CVE-2021-22956 and one or more other CVEs (such as CVE-2020-8300, CVE-2021-22927, and CVE-2021-22920), which require remediation to be applied to each NetScaler at a time: when you select these instances and click Proceed to configuration job workflow, an error message appears telling you to run the config job on each NetScaler at a time.
Step 1: Select configuration
| NetScaler 1 | NetScaler2 |
|---|---|
| Job 1: two SAML actions +two SAML profiles | Job 2: two SAML actions +two SAML profiles |
bind patset $saml_action_patset$ “$saml_action_domain1$” multiple times to ensure that the line appears N times for that SAML action. And change the following variable definition names:
-
saml_action_patset: is the config template variable, and it represents the value of the name of the pattern set (patset) for the SAML action. You can specify the real value in step 3 of the config job workflow. See the section Step 3: Specify variable values in this doc. -
saml_action_domain1: is the config template variable, and it represents the domain name for that specific SAML action. You can specify the real value in step 3, of the config job workflow. See the section Step 3: Specify variable values in this doc.
show samlaction.
bind patset $saml_profile_patset$ “$saml_profile_url1$” multiple times to ensure that the line appears N times for that SAML profile. And change the following variable definition names:
-
saml_profile_patset: is the config template variable, and it represents the value of the name of the pattern set (patset) for the SAML profile. You can specify the real value in step 3, of the config job workflow. See the section Step 3: Specify variable values in this document. -
saml_profile_url1: is the config template variable, and it represents the domain name for that specific SAML profile. You can specify the real value in step 3, of the config job workflow. See the section Step 3: Specify variable values in this document.
show samlidpProfile.
Step 2: Select the instance
Step 3: Specify variable values
-
saml_action_patset: add a name for the SAML action -
saml_action_domain1: enter a domain in the formathttps://<example1.com>/ -
saml_action_name: enter the same of the SAML action for which you are configuring the job -
saml_profile_patset: add a name for the SAML profile -
saml_profile_url1: enter the URL is this formathttps://<example2.com>/cgi/samlauth -
saml_profile_name: enter the same of the SAML profile for which you are configuring the job
cgi/samlauth. It depends on what third-party authorization you have, and accordingly you must put the extension.
Step 4: Preview the configuration
Step 5: Run the job
Points to note for NetScaler Console Express account
Scenario
-
Upgrade all the three NetScaler instances by following the steps given in the Upgrade an instance section in this document.
-
Apply the config patch to one NetScaler at a time, using the configuration job workflow. See the steps given in the Apply configuration commands section in this document.
| Two SAML actions | Two SAML profiles |
|---|---|
| NetScaler configuration | Variable definition for patset | Variable definition for SAML action name | Variable definition for domain |
|---|---|---|---|
| SAML action 1 has one domain | saml_action_patset1 | saml_action_name1 | saml_action_domain1 |
| SAML action 2 has two domains | saml_action_patset2 | saml_action_name2 | saml_action_domain2, saml_action_domain3 |
| NetScaler configuration | Variable definition for patset | Variable definition for SAML profile name | Variable definition for URL |
|---|---|---|---|
| SAML profile 1 has one URL | saml_profile_patset1 | saml_profile_name1 | saml_profile_url1 |
| SAML profile 2 has two URLs | saml_profile_patset2 | saml_profile_name2 | saml_profile_url2, saml_profile_url3 |