CVE-2023-20865

Severity
7.2HIGH
EPSS
0.7%
top 28.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 20
Latest updateOct 1

Description

VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

CVEListV5vmware_aria_operations_for_logs_(formerly_vrealize_log_insight)VMware Aria Operations for Logs (formerly vRealize Log Insight) prior to 8.12
NVDvmware/aria_operations8.6.08.12.0
NVDvmware/cloud_foundation4.04.5

🔴Vulnerability Details

2
CVEList
CVE-2023-20865: VMware Aria Operations for Logs contains a command injection vulnerability2023-04-20
GHSA
GHSA-3frw-92jp-g6w8: VMware Aria Operations for Logs contains a command injection vulnerability2023-04-20

📋Vendor Advisories

2
Red Hat
kernel: media: v4l2-mem2mem: add lock to protect parameter num_rdy2025-10-01
VMware
VMware Aria Operations for Logs (Operations for Logs) update addresses multiple vulnerabilities. (CVE-2023-20864, CVE-2023-20865)2023-04-20