CVE-2021-22021
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
30/08/2021
Last modified:
02/09/2021
Description
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be executed when the victim accesses the shared dashboard link.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | 4.0 (including) | 4.3 (excluding) |
| cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* | 4.0 (including) | 4.8 (including) |
| cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



