First published: Fri Oct 20 2023(Updated: )
VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Aria Operations for Logs | =4.0 | |
VMware Aria Operations for Logs | =5.0 | |
VMware Aria Operations for Logs | =8.10.2 | |
VMware Aria Operations for Logs | =8.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34052 is a deserialization vulnerability in VMware Aria Operations for Logs.
CVE-2023-34052 has a severity value of 7.8, which is classified as high.
CVE-2023-34052 allows a malicious actor with non-administrative access to trigger the deserialization of data, potentially leading to authentication bypass.
CVE-2023-34052 affects VMware Aria Operations for Logs versions 4.0, 5.0, 8.10.2, and 8.12.
To fix CVE-2023-34052, it is recommended to update VMware Aria Operations for Logs to the latest version available.