CVE-2017-4929: XSS
Published Nov 17, 2017
·Updated
VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.
Affected Software
14 affected components
VMware NSX Edge=6.2.0
VMware NSX Edge=6.2.1
VMware NSX Edge=6.2.2
VMware NSX Edge=6.2.3
VMware NSX Edge=6.2.4
VMware NSX Edge=6.2.5
VMware NSX Edge=6.2.6
VMware NSX Edge=6.2.7
VMware NSX Edge=6.2.8
VMware NSX Edge=6.3.0
VMware NSX Edge=6.3.1
VMware NSX Edge=6.3.2
VMware NSX Edge=6.3.3
VMware NSX Edge=6.3.4
Remediation
Event History
Nov 17, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-4929?
CVE-2017-4929 has a moderate severity rating due to the potential for information disclosure through Cross-Site Scripting (XSS).
2
How do I fix CVE-2017-4929?
To mitigate CVE-2017-4929, upgrade VMware NSX Edge to version 6.2.9 or 6.3.5 or later.
3
What versions of VMware NSX Edge are affected by CVE-2017-4929?
CVE-2017-4929 affects VMware NSX Edge versions 6.2.0 through 6.2.8 and 6.3.0 through 6.3.4.
4
What type of vulnerability is CVE-2017-4929?
CVE-2017-4929 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2017-4929 lead to data breaches?
Yes, CVE-2017-4929 could potentially lead to information disclosure, which may assist in further attacks.