An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.
2021-05-14T01:15:06.937
2024-11-21T06:06:31.067
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pulsesecure | virtual_traffic_manager | ≤ 18.1 | Yes |
Application | pulsesecure | virtual_traffic_manager | ≤ 19.1 | Yes |
Application | pulsesecure | virtual_traffic_manager | 18.2 | Yes |
Application | pulsesecure | virtual_traffic_manager | 18.2 | Yes |
Application | pulsesecure | virtual_traffic_manager | 19.2 | Yes |
Application | pulsesecure | virtual_traffic_manager | 19.2 | Yes |
Application | pulsesecure | virtual_traffic_manager | 19.2 | Yes |
Application | pulsesecure | virtual_traffic_manager | 19.3 | Yes |
Application | pulsesecure | virtual_traffic_manager | 20.1 | Yes |
Application | pulsesecure | virtual_traffic_manager | 20.2 | Yes |
Application | pulsesecure | virtual_traffic_manager | 20.3 | Yes |