← VMware

2020 VMware — ESXi/vSphere source code exposed via misconfigured file share

2020 Unknown records affected Share on X

Data compromised

Limited ESXi, Workspace One, and vSphere source fragments per VMware confirmation

Technical writeup

VMware confirmed in April 2020 that limited source code related to ESXi, Workspace One, and vSphere appeared on GitHub after a misconfigured internal file share was reachable from the Internet. The vendor emphasized ongoing integrity reviews and that the exposure was engineering artifacts rather than a customer database leak. BreachHistory indexes the row under the canonical VMware company id with recordsAffected 0.

Root cause

Internet-facing internal file repository misconfiguration

References