First published: Tue Jul 12 2022(Updated: )
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Log Insight | <8.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for VMware vRealize Log Insight is CVE-2022-31655.
The severity of CVE-2022-31655 is medium (5.4).
The affected software for CVE-2022-31655 is VMware vRealize Log Insight, versions prior to 8.8.2.
CVE-2022-31655 is a stored cross-site scripting vulnerability in VMware vRealize Log Insight, versions prior to 8.8.2, due to improper input sanitization in alerts.
To fix CVE-2022-31655, it is recommended to update VMware vRealize Log Insight to version 8.8.2 or later.