CVE Database
/

CVE-2022-21826

Back to search

CVE-2022-21826

Published: Sep 30, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.

VendorProductVersions

n/a

Pulse Connect Secure VPN Server

affected
9.1R14 and below

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now