Database/Control plane, storage & DevOps
VMware Aria Automation (missing access control): An authenticated user reaches remote organizations and workflows they
CVE-2023-34063Control plane, storage & DevOpscurated
Impact
An authenticated user reaches remote organizations and workflows they should not see - a tenancy-boundary failure inside the automation platform, with scope change.
Who can reach it
Any authenticated Aria Automation user.
What to do
Apply the fix per VMSA-2024-0001. Appliance patch; review org/workflow assignments afterwards for signs of cross-org access.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.