First published: Fri Aug 04 2023(Updated: )
VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Horizon Client | =2006 | |
Vmware Horizon Client | =2012 | |
Vmware Horizon Client | =2103 | |
Vmware Horizon Client | =2106 | |
Vmware Horizon Client | =2111 | |
Vmware Horizon Client | =2111.1 | |
Vmware Horizon Client | =2203 | |
Vmware Horizon Client | =2212 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34037 is a HTTP request smuggling vulnerability in VMware Horizon Server.
The severity of CVE-2023-34037 is medium.
CVE-2023-34037 affects VMware Horizon Client versions 2006, 2012, 2103, 2106, 2111, 2111.1, 2203, and 2212.
A malicious actor with network access can exploit CVE-2023-34037 by performing HTTP smuggle requests.
Yes, VMware has released a security advisory with fixes for CVE-2023-34037. Please refer to the advisory for more details.