CVE-2023-20891 is an information disclosure vulnerability in VMware Tanzu Application Service for VMs and Isolation Segment, where CF API admin credentials are logged in hex encoding within platform system audit logs. This medium-severity vulnerability (CVSS 6.5) allows a malicious non-admin user with audit log access to retrieve these credentials, potentially leading to the deployment of malicious applications. While a default deployment restricts non-admin access to these logs, the vulnerability has garnered some community discussion and media coverage, though there is currently no evidence of active exploitation or public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.11.0, < 2.11.35CPE matchmatch criteria | cpe:2.3:a:vmware:isolation_segment:*:*:*:*:*:*:*:* | ||
>= 2.13.0, < 2.13.20CPE matchmatch criteria | cpe:2.3:a:vmware:isolation_segment:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.13CPE matchmatch criteria | cpe:2.3:a:vmware:isolation_segment:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.4CPE matchmatch criteria | cpe:2.3:a:vmware:isolation_segment:*:*:*:*:*:*:*:* | ||
>= 2.11.0, < 2.11.42CPE matchmatch criteria | cpe:2.3:a:vmware:tanzu_application_service_for_virtual_machines:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.