CVE-2021-31922
Last modified
CVE-2021-31922 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pulsesecure | Virtual Traffic Manager | <= 18.1 |
| Pulsesecure | Virtual Traffic Manager | >= 18.3, <= 19.1 |
| Pulsesecure | Virtual Traffic Manager | 18.2 |
| Pulsesecure | Virtual Traffic Manager | 19.2 |
| Pulsesecure | Virtual Traffic Manager | 19.3 |
| Pulsesecure | Virtual Traffic Manager | 20.1 |
| Pulsesecure | Virtual Traffic Manager | 20.2 |
| Pulsesecure | Virtual Traffic Manager | 20.3 |
References
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44790Exploit, Patch, Vendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44790Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31922?
How severe is CVE-2021-31922?
How do I fix CVE-2021-31922?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31916An out-of-bounds (OOB) memory write flaw was found in list_d…6.7
- CVE-2021-31917A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.…9.8
- CVE-2021-31918A flaw was found in tripleo-ansible version as shipped in Re…7.5
- CVE-2021-31919An issue was discovered in the rkyv crate before 0.6.0 for R…7.5
- CVE-2021-31920Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exp…6.5
- CVE-2021-31921Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotel…9.8
- CVE-2021-31923Ping Identity PingAccess before 5.3.3 allows HTTP request sm…5.3
- CVE-2021-31924Yubico pam-u2f before 1.1.1 has a logic issue that, dependin…6.8
- CVE-2021-31925Pexip Infinity 25.x before 25.4 has Improper Input Validatio…7.5
- CVE-2021-31926AMP Application Deployment Service in CubeCoders AMP 2.1.x b…6.5
- CVE-2021-31927An Insecure Direct Object Reference (IDOR) vulnerability in …4.3
- CVE-2021-31928Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows a…8.8
Are you affected by CVE-2021-31922?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
