#VU71488 Deserialization of Untrusted Data in Aria Operations for Logs (formerly vRealize Log Insight) - CVE-2022-31710
Published: January 24, 2023 / Updated: February 13, 2023
Aria Operations for Logs (formerly vRealize Log Insight)
VMware, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insecure input validation when processing serialized data within the addClusterCACertificate function. A remote non-authenticated attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.