id: CVE-2022-31711 info: name: VMware vRealize Log Insight < v8.10.2 - Information Disclosure author: DhiyaneshDK severity: medium description: | VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication. impact: | Attackers can access sensitive session and application data, leading to potential information leakage and security breaches." remediation: | Apply the latest security patches and updates provided by VMware to mitigate this vulnerability. reference: - http://packetstormsecurity.com/files/174606/VMware-vRealize-Log-Insight-Unauthenticated-Remote-Code-Execution.html - https://github.com/horizon3ai/vRealizeLogInsightRCE classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cve-id: CVE-2022-31711 epss-score: 0.21657 epss-percentile: 0.97371 cpe: cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* metadata: vendor: vmware product: vrealize_log_insight shodan-query: http.title:"vrealize log insight" fofa-query: title="vrealize log insight" google-query: intitle:"vrealize log insight" tags: cve,cve2022,vmware,exposure,passive,vkev,vuln http: - method: GET path: - "{{BaseURL}}/i18n/component/JS?locale=en-US" - "{{BaseURL}}/api/v1/version" stop-at-first-match: true matchers-condition: and matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_any(body, "logInsight", "releaseName\":")' condition: and - type: dsl dsl: - "compare_versions(version, '>= 8.0.0', '< 8.10.2')" - "compare_versions(version, '>= 3.0', '< 4.8')" condition: or extractors: - type: regex part: body name: version group: 1 regex: - 'version"\s*:\s*"([0-9.]+)' # digest: 4a0a004730450220214392ac22c622c60a0cdafd2ea24b8c8eb92983229006df883311f87871973c022100f74717e6103e65cee83cc78930dce7e6327613bb63a8ba0f88c5178faef8f6cd:922c64590222798bb761d5b6d8e72950