VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor with man-in-the-middle (MITM) network positioning between vCenter server and the virtual machine may be able to bypass SAML token signature verification, to perform VMware Tools Guest Operations. References: https://www.vmware.com/security/advisories/VMSA-2023-0019.html https://www.openwall.com/lists/oss-security/2023/08/31/1 https://github.com/vmware/open-vm-tools/blob/CVE-2023-20900.patch/CVE-2023-20900.patch
Created open-vm-tools tracking bugs for this issue: Affects: fedora-all [bug 2236578]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions Via RHSA-2023:5213 https://access.redhat.com/errata/RHSA-2023:5213
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat Enterprise Linux 8.2 Telecommunications Update Service Via RHSA-2023:5210 https://access.redhat.com/errata/RHSA-2023:5210
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2023:5216 https://access.redhat.com/errata/RHSA-2023:5216
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:5220 https://access.redhat.com/errata/RHSA-2023:5220
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2023:5217 https://access.redhat.com/errata/RHSA-2023:5217
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:5218 https://access.redhat.com/errata/RHSA-2023:5218
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5312 https://access.redhat.com/errata/RHSA-2023:5312
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5313 https://access.redhat.com/errata/RHSA-2023:5313
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.7 Advanced Update Support Via RHSA-2024:5315 https://access.redhat.com/errata/RHSA-2024:5315