
VMware has fixed an information disclosure vulnerability in VMware Tanzu Application Service for VMs (TAS for VMs) and Isolation Segment caused by credential logging and exposure via system audit logs.
See also: Akira ransomware: Linux version targets VMware ESXi servers
TAS for VMs helps enterprises automate application deployment on premises or in public and private clouds (e.g. vSphere, AWS, Azure, GCP, OpenStack).
Dubbed CVE-2023-20891, the security flaw being addressed today by VMware would allow remote attackers with low privileges to gain access to Cloud Foundry API administrator credentials on unpatched systems in low-sophistication attacks that require no user interaction.
This is because, in non-updated TAS for VMs instances, the hexadecimal encoded CF API administrator credentials are registered in the platform system control files.
Attackers who exploit this vulnerability can use the stolen credentials to push malicious versions of applications.
"A malicious non-admin user with access to the platform's system audit logs can gain access to hexadecimal-encoded CF API administrator credentials and can push new malicious versions of an application," VMware says.
Fortunately, as highlighted by VMware, non-admin users do not have access to system audit logs in typical deployment configurations.

Suggestion: VMware fixes critical zero-day exploit chain
It is recommended to switch administrator credentials
However, the company still advises all TAS for VMs users affected by CVE-2023-20891 to change their CF API administrator credentials to ensure that attackers cannot use the leaked passwords.
VMware provides detailed instructions on changing Cloud Foundry User Account and Authentication (UAA) administrator credentials in this support document.
Last month, VMware addressed high-severity security flaws in vCenter Server that allowed code execution and authentication bypass.
It also fixed an ESXi that a Chinese-backed hacker group exploited to backdoor Windows and Linux virtual machines in data theft attacks.
Recently, the company warned customers that exploit code is now available for a critical RCE vulnerability in the VMware Aria Operations for Logs analysis tool.
Read also: Linux version of RTM Locker ransomware targets VMware ESXi servers
source of information:bleepingcomputer.com
