VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.
References
Link | Resource |
---|---|
https://www.vmware.com/security/advisories/VMSA-2023-0021.html | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: vmware
Published: 2023-10-20T04:11:45.105Z
Updated: 2023-10-20T04:11:45.105Z
Reserved: 2023-05-25T17:21:56.203Z
Link: CVE-2023-34052
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-20T05:15:08.420
Modified: 2023-10-30T15:27:41.487
Link: CVE-2023-34052
JSON object: View
Redhat Information
No data.
CWE