CVE-2021-21973: medium-severity vulnerability in VMware vCenter Server
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
The vSphere Client contains a flaw that allows attackers to manipulate the server into making unauthorized requests to internal systems, potentially exposing sensitive information. An attacker with network access can exploit this by sending specially crafted requests to vCenter Server.
SSRF vulnerability in vCenter Server plugin due to improper URL validation in the HTML5 vSphere Client. Attackers with network access to port 443 can send malicious POST requests to trigger server-side requests to arbitrary internal resources, resulting in information disclosure. Affected versions: vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n, and vCloud Foundation 4.x before 4.2, 3.x before 3.10.1.2.
The full analysis of this CVE is available in Portuguese →