First published: Mon Aug 30 2021(Updated: )
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be executed when the victim accesses the shared dashboard link.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | >=4.0<4.3 | |
VMware vRealize Log Insight | >=4.0<=4.8 | |
VMware vRealize Log Insight | >=8.0.0<8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this VMware vRealize Log Insight vulnerability is CVE-2021-22021.
The severity of CVE-2021-22021 is medium, with a CVSS score of 5.4.
The affected software versions range from 8.x prior to 8.4 of VMware vRealize Log Insight.
The CWE categories for this vulnerability are CWE-79 (Cross-Site Scripting) and CWE-20 (Improper Input Validation).
An attacker with user privileges can exploit this vulnerability by injecting a malicious payload via the Log Insight UI.