CVE-2023-34052

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
20/10/2023
Last modified:
30/10/2023

Description

VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:aria_operations_for_logs:4.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_operations_for_logs:5.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_operations_for_logs:8.10.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_operations_for_logs:8.12:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools