CVE-2023-20865: Command Injection
Published Apr 20, 2023
·Updated
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
Affected Software
2 affected components
VMware Aria Operations for Logs>=8.6.0<8.12.0
VMware Cloud Foundation>=4.0<=4.5
Event History
Apr 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-20865.
2
What is the title of the vulnerability?
The title of the vulnerability is 'VMware Aria Operations for Logs contains a command injection vulnerability'.
3
What is the description of the vulnerability?
The vulnerability allows a malicious actor with administrative privileges in VMware Aria Operations for Logs to execute arbitrary commands as root.
4
What is the affected software?
The affected software includes VMware Aria Operations for Logs (versions between 8.6.0 and 8.12.0) and VMware Cloud Foundation (versions between 4.0 and 4.5).
5
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 7.2.