CVE-2021-31922
14.05.2021, 01:15
An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.
Vendor | Product | Version |
---|---|---|
pulsesecure | virtual_traffic_manager | 𝑥 ≤ 18.1 |
pulsesecure | virtual_traffic_manager | 18.3 ≤ 𝑥 ≤ 19.1 |
pulsesecure | virtual_traffic_manager | 18.2 |
pulsesecure | virtual_traffic_manager | 18.2:r1 |
pulsesecure | virtual_traffic_manager | 19.2 |
pulsesecure | virtual_traffic_manager | 19.2:r1 |
pulsesecure | virtual_traffic_manager | 19.2:r2 |
pulsesecure | virtual_traffic_manager | 19.3 |
pulsesecure | virtual_traffic_manager | 20.1 |
pulsesecure | virtual_traffic_manager | 20.2 |
pulsesecure | virtual_traffic_manager | 20.3 |
𝑥
= Vulnerable software versions