CVE-2023-34052: VMware Aria Operations For Logs
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.
Affected products
- VMware Aria Operations For Logs: version 4.0 only; version 5.0 only; version 8.10.2 only; version 8.12 only
Published 2023-10-20. Last modified 2026-06-17.