HomeSecurityVMware: Fixes bug that exposes CF API admin credentials in audit...

VMware: Fixes bug that exposes CF API admin credentials in audit logs

VMware

VMware has fixed an information disclosure vulnerability in VMware Tanzu Application Service for VMs (TAS for VMs) and Isolation Segment caused by credential logging and exposure via system audit logs. 

See also: Akira ransomware: Linux version targets VMware ESXi servers

TAS for VMs helps enterprises automate application deployment on premises or in public and private clouds (e.g. vSphere, AWS, Azure, GCP, OpenStack).

Dubbed CVE-2023-20891, the security flaw being addressed today by VMware would allow remote attackers with low privileges to gain access to Cloud Foundry API administrator credentials on unpatched systems in low-sophistication attacks that require no user interaction.

This is because, in non-updated TAS for VMs instances, the hexadecimal encoded CF API administrator credentials are registered in the platform system control files.

Attackers who exploit this vulnerability can use the stolen credentials to push malicious versions of applications.

"A malicious non-admin user with access to the platform's system audit logs can gain access to hexadecimal-encoded CF API administrator credentials and can push new malicious versions of an application," VMware says.

Fortunately, as highlighted by VMware, non-admin users do not have access to system audit logs in typical deployment configurations.

VMware

Suggestion: VMware fixes critical zero-day exploit chain

It is recommended to switch administrator credentials

However, the company still advises all TAS for VMs users affected by CVE-2023-20891 to change their CF API administrator credentials to ensure that attackers cannot use the leaked passwords.

VMware provides detailed instructions on changing Cloud Foundry User Account and Authentication (UAA) administrator credentials in this support document.

Last month, VMware addressed high-severity security flaws in vCenter Server that allowed code execution and authentication bypass.

It also fixed an ESXi that a Chinese-backed hacker group exploited to backdoor Windows and Linux virtual machines in data theft attacks.

Recently, the company warned customers that exploit code is now available for a critical RCE vulnerability in the VMware Aria Operations for Logs analysis tool.

Read also: Linux version of RTM Locker ransomware targets VMware ESXi servers

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS