Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85qj-2cfq-3wp8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.

EPSS

Процентиль: 41%
0.00189
Низкий

7.5 High

CVSS3

Дефекты

CWE-335

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.

EPSS

Процентиль: 41%
0.00189
Низкий

7.5 High

CVSS3

Дефекты

CWE-335