CVE-2023-20891: VMware Tanzu Application Service for VMs and Isolation Segment information disclosure vulnerability
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials and can push new malicious versions of an application. In a default deployment non-admin users do not have access to the platform system audit logs.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20891?
CVE-2023-20891 is an information disclosure vulnerability in VMware Tanzu Application Service for VMs and Isolation Segment.
What is the severity of CVE-2023-20891?
CVE-2023-20891 has a severity rating of 6.5 (Medium).
How does CVE-2023-20891 affect VMware Tanzu Application Service for VMs?
CVE-2023-20891 allows a malicious non-admin user with access to the platform system audit logs to access hex encoded CF API credentials.
How can I fix CVE-2023-20891?
To fix CVE-2023-20891, upgrade to a version of VMware Tanzu Application Service for VMs or Isolation Segment that is not affected by the vulnerability.
Where can I find more information about CVE-2023-20891?
More information about CVE-2023-20891 can be found in the VMWare security advisory VMSA-2023-0016.