First published: Wed Oct 13 2021(Updated: )
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior to exporting a CSV sheet through Log Insight which could be executed in user's environment.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | >=4.0.0<=4.3.1 | |
VMware vRealize Log Insight | >8.0.0<8.60 | |
Vmware Vrealize Suite Lifecycle Manager | >=8.0.0<=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-22035.
The severity of CVE-2021-22035 is medium, with a severity value of 4.3.
VMware vRealize Log Insight (8.x prior to 8.6) is affected by CVE-2021-22035.
An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior to exporting a CSV sheet through Log Insight.
Apply the necessary security patch or upgrade to a version that is not affected by the vulnerability.