First published: Wed Sep 13 2023(Updated: )
It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker could possibly use this issue to bypass SAML token signature verification and perform VMware Tools Guest Operations.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/open-vm-tools | <2:12.1.5-3ubuntu0.23.04.2 | 2:12.1.5-3ubuntu0.23.04.2 |
=23.04 | ||
All of | ||
ubuntu/open-vm-tools | <2:12.1.5-3~ubuntu0.22.04.3 | 2:12.1.5-3~ubuntu0.22.04.3 |
=22.04 | ||
All of | ||
ubuntu/open-vm-tools | <2:11.3.0-2ubuntu0~ubuntu20.04.6 | 2:11.3.0-2ubuntu0~ubuntu20.04.6 |
=20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-6365-1
Open VM Tools vulnerability
Open VM Tools incorrectly handles SAML tokens, allowing a remote attacker to bypass SAML token signature verification and perform VMware Tools Guest Operations.
Open VM Tools version 2:12.1.5-3ubuntu0.23.04.2, version 2:12.1.5-3~ubuntu0.22.04.3, and version 2:11.3.0-2ubuntu0~ubuntu20.04.6 on Ubuntu 23.04, 22.04, and 20.04 respectively.
This vulnerability is not assigned a severity rating.
Update to Open VM Tools version 2:12.1.5-3ubuntu0.23.04.2, 2:12.1.5-3~ubuntu0.22.04.3, or 2:11.3.0-2ubuntu0~ubuntu20.04.6 depending on your Ubuntu version.