{ "schema_version": "1.4.0", "id": "GHSA-2m46-g734-85f6", "modified": "2024-02-27T21:31:21Z", "published": "2022-05-24T21:59:46Z", "aliases": [ "CVE-2019-11507" ], "details": "In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11507" }, { "type": "WEB", "url": "https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study" }, { "type": "WEB", "url": "https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf" }, { "type": "WEB", "url": "https://kb.pulsesecure.net/?atype=sa" }, { "type": "WEB", "url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101" }, { "type": "WEB", "url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516" }, { "type": "WEB", "url": "https://www.kb.cert.org/vuls/id/927237" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/108073" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-05-08T17:29:00Z" } }