← Back

CVE-2022-21826

nvd nist
Published: Sep 30, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.

Affected (39)

1 product
Connect Secure
1 product
Pulse Connect Secure
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 9.1
Version 9.1 r1.0
Version 9.1 r10.0
Version 9.1 r10.2
Version 9.1 r11.0
Version 9.1 r11.1
Version 9.1 r11.3
Version 9.1 r11.4
Version 9.1 r12.1
Version 9.1 r12.2
Version 9.1 r12
Version 9.1 r13
Version 9.1 r15
Version 9.1 r1
Version 9.1 r2.0
Version 9.1 r2
Version 9.1 r3.0
Version 9.1 r3
Version 9.1 r4.0
Version 9.1 r4.1
Version 9.1 r4.2
Version 9.1 r4.3
Version 9.1 r4
Version 9.1 r5.0
Version 9.1 r5
Version 9.1 r6.0
Version 9.1 r6
Version 9.1 r7.0
Version 9.1 r7
Version 9.1 r8.0
Version 9.1 r8.1
Version 9.1 r8.2
Version 9.1 r8.4
Version 9.1 r8
Version 9.1 r9.0
Version 9.1 r9.1
Version 9.1 r9.2
Version 9.1 r9
Before 9.1

Timeline

No history available yet.