CSV Injection Vulnerability in VMware vRealize Log Insight
CVE-2021-22035
4.3MEDIUM
What is CVE-2021-22035?
The CSV injection vulnerability in VMware vRealize Log Insight affects versions 8.x before 8.6. It allows an authenticated attacker with non-administrative privileges to introduce untrusted data during the interactive analytics export process. If exported, this malicious data could be executed in a user's environment, potentially compromising sensitive information. To mitigate this risk, users should perform strong input validation and ensure that exports are conducted in a secure context.
Affected Version(s)
VMware vRealize Log Insight VMware vRealize Log Insight (8.x prior to 8.6)