QID 376731

Date Published: 2022-11-10

QID 376731: VMware vRealize Log Insight Cross-Site Scripting (XSS) Vulnerability (VMSA-2022-0019)

VRealize Log Insight is a log collection and analytics virtual appliance that enables administrators to collect, view, manage and analyze syslog data.

Affected Versions:
VMware vRealize Log Insight version prior to 8.8.2

QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of VMware vRealize Log Insight Automation.

A malicious actor with admin privileges may be able to inject malicious code into alerts and configurations due to improper input sanitization.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Vendor has released patch to address this vulnerability. Refer to Vmware security advisory VMSA-2021-0019

    CVEs related to QID 376731

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0019 URL Logo www.vmware.com/security/advisories/VMSA-2022-0019.html