CVE-2021-21978

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:view_planner:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:view_planner:4.6:-:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-434 CWE-20
CWE-862

Information

Published : 2021-03-03 18:15

Updated : 2024-02-04 21:23


NVD link : CVE-2021-21978

Mitre link : CVE-2021-21978

CVE.ORG link : CVE-2021-21978


JSON object : View

Products Affected

vmware

  • view_planner
CWE
CWE-20

Improper Input Validation

CWE-862

Missing Authorization