First published: Thu Jul 04 2024(Updated: )
VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Director | >=4.0.0<4.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22277 is considered a high severity vulnerability due to the potential for HTML injection attacks by malicious actors.
To fix CVE-2024-22277, apply the latest security patches provided by VMware for Cloud Director Availability.
CVE-2024-22277 affects VMware Cloud Director versions from 4.0.0 to 4.7.2.
CVE-2024-22277 can enable malicious actors to execute crafted HTML tags within replication tasks, potentially leading to unauthorized access or data manipulation.
Yes, network access to VMware Cloud Director Availability is necessary for an attacker to exploit CVE-2024-22277.