First published: Mon Apr 11 2022(Updated: )
The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Photon OS | <2022-02-16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22055 is a vulnerability in the SchedulerServer of Vmware Photon OS that allows remote attackers to inject logs and insert malicious data.
CVE-2021-22055 has a severity score of 5.3, which is considered medium.
Remote attackers can exploit CVE-2021-22055 by injecting logs through the package parameter and inserting malicious data.
Vmware Photon OS versions before 2022-02-16 are affected by CVE-2021-22055.
Yes, a fix for CVE-2021-22055 is available. Please refer to the official reference for detailed mitigation steps.