CVE-2022-31654: XSS
Published Jul 12, 2022
·Updated
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.
Affected Software
1 affected component
VMware vRealize Log Insight<8.8.2
Remediation
Event History
Jul 12, 2022
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-31654.
2
What is the severity of CVE-2022-31654?
The severity of CVE-2022-31654 is medium with a CVSS score of 5.4.
3
What is affected by CVE-2022-31654?
VMware vRealize Log Insight versions prior to 8.8.2 are affected by CVE-2022-31654.
4
How does CVE-2022-31654 work?
CVE-2022-31654 is a stored cross-site scripting (XSS) vulnerability that occurs due to improper input sanitization in configurations.
5
Is there a fix for CVE-2022-31654?
Yes, the fix for CVE-2022-31654 is available in VMware vRealize Log Insight version 8.8.2.