QID 379483

Date Published: 2024-03-20

QID 379483: VMware Cloud Director Authentication Bypass Vulnerability (VMSA-2024-0007)

VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance. .

Affected Versions:
VMware Cloud Director version 10.4.x, 10.5.x

Fixed version
Upgrade to 10.5.1.1

QID Detection Logic (Authenticated):
This QID checks for vulnerable versions of VMware Cloud Director with build version on the target.

Successful exploit may lead to information disclosure

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    VMware has released patches for these vulnerabilities.

    Refer to VMware advisory VMSA-2024-0007

    CVEs related to QID 379483

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2024-0007 URL Logo www.vmware.com/security/advisories/VMSA-2024-0007.html