CVE-2020-3953: Input Validation
Published Apr 15, 2020
·Updated
Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
Affected Software
1 affected component
VMware vRealize Log Insight<8.1.0
Event History
Apr 15, 2020
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2020-3953.
2
What is the severity of CVE-2020-3953?
The severity of CVE-2020-3953 is medium with a CVSS score of 4.8.
3
What is the affected software?
The affected software is VMware vRealize Log Insight prior to version 8.1.0.
4
What is the vulnerability description?
This vulnerability is a Cross Site Scripting (XSS) vulnerability that exists in VMware vRealize Log Insight due to improper input validation.
5
How can I fix CVE-2020-3953?
To fix CVE-2020-3953, it is recommended to update VMware vRealize Log Insight to version 8.1.0 or later.