CVE-2021-22021
published 2021-08-30CVE-2021-22021: VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.47%
37.3th percentile
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be executed when the victim accesses the shared dashboard link.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 4.0 < 4.3 | 4.3 |
| vmware | vrealize_log_insight | 4.0 – 4.8 | — |
| vmware | vrealize_log_insight | >= 8.0.0 < 8.4 | 8.4 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vRealize Log Insight updates address Cross Site Scripting (XSS) vulnerability (CVE-2021-22021)
vendor_vmware·2021-08-24·CVSS 5.4
CVE-2021-22021 [MEDIUM] VMware vRealize Log Insight updates address Cross Site Scripting (XSS) vulnerability (CVE-2021-22021)
VMSA-2021-0019: VMware vRealize Log Insight updates address Cross Site Scripting (XSS) vulnerability (CVE-2021-22021)
VMware vRealize Log Insight contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.5.
CVEs: CVE-2021-22021
Affected products: VMware Aria, VMware Cloud Foundation, VMware vRealize
GHSA
GHSA-mw4g-p3x5-fwh9: VMware vRealize Log Insight (8
ghsa_unreviewed·2022-05-24
CVE-2021-22021 [MEDIUM] CWE-79 GHSA-mw4g-p3x5-fwh9: VMware vRealize Log Insight (8
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be executed when the victim accesses the shared dashboard link.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-30
Published