Symptoms:
When a Nessus scan is performed on a VM that is part of an Aria Operations for Logs 8.14.x/8.16 cluster, the scan reports that the following library is detected and may show as susceptible to Authentication Bypass vulnerability (VMSA-2023-0021):
/usr/lib/loginsight/application/3rd_party/vI18nManager-logInsight-8.12.latest.jar
This incorrectly detects that the product version is also 8.12, but in fact that jar version can be different from the installed product version.
This issue is considered a false positive as VMSA-2023-0021.
Reference:
Incorrect Nessus scan reports -- VMSA-2023-0021
"This release resolves CVE-2023-34051, CVE-2023-34052. For more information on these vulnerabilities and their impact on VMware products, please see VMSA-2023-0021 ."
VMware Aria Operations for Logs 8.14.x
Nessus scan incorrectly reports Authentication Bypass vulnerability (VMSA-2023-0021). You can ignore this result if you are already on Aria Operations for Logs 8.14 and above.