An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX.
| Software | From | Fixed in |
|---|---|---|
| ivanti / connect_secure | 8.3-r1 | 8.3-r1.x |
| ivanti / connect_secure | 8.3-r2 | 8.3-r2.x |
| ivanti / connect_secure | 8.3-r2.1 | 8.3-r2.1.x |