CVE-2024-22277: XSS
VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22277?
CVE-2024-22277 is considered a high severity vulnerability due to the potential for HTML injection attacks by malicious actors.
How do I fix CVE-2024-22277?
To fix CVE-2024-22277, apply the latest security patches provided by VMware for Cloud Director Availability.
Which versions of VMware Cloud Director are affected by CVE-2024-22277?
CVE-2024-22277 affects VMware Cloud Director versions from 4.0.0 to 4.7.2.
What kind of attacks can CVE-2024-22277 enable?
CVE-2024-22277 can enable malicious actors to execute crafted HTML tags within replication tasks, potentially leading to unauthorized access or data manipulation.
Is network access required for CVE-2024-22277 exploitation?
Yes, network access to VMware Cloud Director Availability is necessary for an attacker to exploit CVE-2024-22277.