- From the developer tools console access in browser it was observed that iframe which has both allow-scripts and allow-same-origin for its sandbox attribute can escape its sandboxing.
- Below are the observation
An iframe which has both allow-scripts and allow-same-origin for its sandbox attribute can escape its sandboxing.
VMware Transport v1.3.6 Initialized with Id: eventbus-25c43cf5-803a-4c14-alec-e01e9471af8d-1.3.6, Hi! [EventBus] (HH:MM:SS PM)
Access to XMLHttpRequest at 'https://feedback.esp.vmware.com/api/feedback/v1/trigger-events?client id=esp-prod-258-qczdg&component=static' from origin 'https://<vcsa-fqdn>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on
the requested resource.
X {headers: g, status: 0, statusText: 'Unknown Error', url: 'https://feedback.esp. vmware.com/api/feedback/v1/tr .. nts?client_id=esp-prod-258-qczdg&component=static', ok: false, ... }
GET https://feedback.esp.vmware.com/api/feedback/v1/trigger-events?client id=esp-prod-258-qczdg&component=static net :: ERR_FAILED 200 (OK)
Access to XMLHttpRequest at 'https://apigw. vmware.com/v1/m7/api/lumos/user/user-details?client id=esp-prod-258-qczdg' from origin 'https://<vcsa-fqdn>' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No
'Access-Control-Allow-Origin' header is present on the requested resource.
notificationService :: error
message =
stack trace = undefined
GET https://apigw.vmware.com/v1/m7/api/lumos/user/user-details?client id=esp-prod-258-qczdg net :: ERR_FAILED
A [GroupMarkerNotSet(crbug.com/242999) !: A07027004C470000]Automatic fallback to software WebGL has been deprecated. Please use the -- enable-unsafe-swiftshader flag to opt in to lower security guarantees for trusted content.
vCenter 8.x
VMware is aware of this issue and working to resolve this in a vCenter future release.