Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-20865: VMSA-2023-0007

VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.

CVE
#vulnerability#vmware#auth#zero_day

Advisory ID: VMSA-2023-0007

CVSSv3 Range: 7.2-9.8

Issue Date: 2023-04-20

Updated On: 2023-04-20 (Initial Advisory)

CVE(s): CVE-2023-20864, CVE-2023-20865

Synopsis: VMware Aria Operations for Logs (Operations for Logs) update addresses multiple vulnerabilities. (CVE-20864, CVE-20865)

****1. Impacted Products****

VMware Aria Operations for Logs (formerly vRealize Log Insight)

****2. Introduction****

Multiple vulnerabilities in VMware Aria Operations for Logs were privately reported to VMware. Updates and workarounds are available to address these vulnerabilities in affected VMware products.

****3a. VMware Aria Operations for Logs Deserialization Vulnerability (CVE-2023-20864)****

VMware Aria Operations for Logs contains a deserialization vulnerability. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

To remediate CVE-2023-20864 apply the updates listed in the ‘Fixed Version’ column of the ‘Response Matrix’ below.

VMware would like to thank Anonymous working with Trend Micro Zero Day Initiative for reporting this issue to us.

****3b. VMware Aria Operations for Logs Command Injection Vulnerability (CVE-2023-20865)****

VMware Aria Operations for Logs contains a command injection vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.

A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.

To remediate CVE-2023-20865 apply the updates listed in the ‘Fixed Version’ column of the ‘Response Matrix’ below.

VMware would like to thank Y4er & MoonBack of 埃文科技 for reporting this vulnerability to us.

Product

Version

Running On

CVE Identifier

CVSSv3

Severity

Fixed Version

Workarounds

Additional Documentation

VMware Aria Operations for Logs (Operations for Logs)

8.12

Any

CVE-2023-20864, CVE-2023-20865

N/A

N/A

Unaffected

None

KB91831

VMware Aria Operations for Logs (Operations for Logs)

8.10.2

Any

CVE-2023-20864, CVE-2023-20865

9.8, 7.2

critical

8.12

None

KB91831

VMware Aria Operations for Logs (Operations for Logs)

8.10

Any

CVE-2023-20864

N/A

N/A

Unaffected

None

KB91831

VMware Aria Operations for Logs (Operations for Logs)

8.10

Any

CVE-2023-20865

7.2

important

8.12

None

KB91831

VMware Aria Operations for Logs (Operations for Logs)

8.8.x

Any

CVE-2023-20864

N/A

N/A

Unaffected

None

KB91831

VMware Aria Operations for Logs (Operations for Logs)

8.8.x

Any

CVE-2023-20865

7.2

important

8.12

None

KB91831

VMware Aria Operations for Logs (Operations for Logs)

8.6.x

Any

CVE-2023-20864

N/A

N/A

Unaffected

None

KB91831

VMware Aria Operations for Logs (Operations for Logs)

8.6.x

Any

CVE-2023-20865

7.2

important

8.12

None

KB91831

VMware Cloud Foundation (VMware Aria Operations for Logs)

4.x

Any

CVE-2023-20864, CVE-2023-20865

9.8, 7.2

critical

KB91865

KB91865

KB91831

****4. References****

****5. Change Log****

2023-04-20 VMSA-2023-0007

Initial security advisory.

****6. Contact****

Related news

VMware Releases Critical Patches for Workstation and Fusion Software

VMware has released updates to resolve multiple security flaws impacting its Workstation and Fusion software, the most critical of which could allow a local attacker to achieve code execution. The vulnerability, tracked as CVE-2023-20869 (CVSS score: 9.3), is described as a stack-based buffer-overflow vulnerability that resides in the functionality for sharing host Bluetooth devices with the

Cisco and VMware Release Security Updates to Patch Critical Flaws in their Products

Cisco and VMware have released security updates to address critical security flaws in their products that could be exploited by malicious actors to execute arbitrary code on affected systems. The most severe of the vulnerabilities is a command injection flaw in Cisco Industrial Network Director (CVE-2023-20036, CVSS score: 9.9), which resides in the web UI component and arises as a result of

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907