CVE-2023-34052: High severity vmware vrealize operations vulnerability
Published Oct 20, 2023
·Updated
VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.
Affected Software
4 affected components
VMware Aria Operations for Logs=4.0
VMware Aria Operations for Logs=5.0
VMware Aria Operations for Logs=8.10.2
VMware Aria Operations for Logs=8.12
Remediation
Event History
Oct 20, 2023
CVE Published
via MITRE·04:11 AM
Data Sourced
via MITRE·04:11 AM
DescriptionWeakness
Data Sourced
05:15 AM
Description
Frequently Asked Questions
1
What is CVE-2023-34052?
CVE-2023-34052 is a deserialization vulnerability in VMware Aria Operations for Logs.
2
What is the severity of CVE-2023-34052?
CVE-2023-34052 has a severity value of 7.8, which is classified as high.
3
How does CVE-2023-34052 impact VMware Aria Operations for Logs?
CVE-2023-34052 allows a malicious actor with non-administrative access to trigger the deserialization of data, potentially leading to authentication bypass.
4
Which versions of VMware Aria Operations for Logs are affected by CVE-2023-34052?
CVE-2023-34052 affects VMware Aria Operations for Logs versions 4.0, 5.0, 8.10.2, and 8.12.
5
How can I fix CVE-2023-34052?
To fix CVE-2023-34052, it is recommended to update VMware Aria Operations for Logs to the latest version available.