The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
| Software | From | Fixed in |
|---|---|---|
| vmware / vrealize_log_insight | 3.0 | 4.8.x |
| vmware / vrealize_log_insight | 8.0.0 | 8.10.2 |