漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
VMSA-2025-0008: VMware Aria automation updates address a DOM based Cross-site scripting vulnerability (CVE-2025-22249)
Vulnerability Description
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
VMware Aria Automation 安全漏洞
Vulnerability Description
VMware Aria Automation是美国威睿(VMware)公司的一个现代工作流自动化平台,可简化并自动执行复杂的数据中心基础架构任务,以提高可延展性和敏捷性。 VMware Aria Automation存在安全漏洞,该漏洞源于DOM型跨站脚本,可能导致访问令牌窃取。
CVSS Information
N/A
Vulnerability Type
N/A