PT-2021-7541 · Vmware · Vmware Vrealize Log Insight

Marcin Kot

+1

·

Published

2021-08-30

·

Updated

2022-08-24

·

CVE-2021-22021

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions VMware vRealize Log Insight versions 8.x prior to 8.4
Description The issue is due to improper user input validation, allowing an attacker with user privileges to inject a malicious payload via the Log Insight UI. This payload would be executed when the victim accesses the shared dashboard link, potentially impacting the confidentiality and integrity of protected information. The vulnerability can be exploited by a remote attacker using a specially crafted link.
Recommendations For versions 8.x prior to 8.4, update to version 8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Log Insight UI to minimize the risk of exploitation. Avoid sharing dashboard links from untrusted sources until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-07429
CVE-2021-22021

Affected Products

Vmware Vrealize Log Insight