VMware vRealize SSRF·ì϶£¨CVE-2021-21975£©
°ä²¼¹¦·ò 2021-03-310x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-21975 | ʱ ¼ä | 2021-03-31 |
Àà ÐÍ | SSRF | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

Vmware vRealize Operations ManagerÊÇÕë¶ÔvmwareÐé¹¹»¯Æ½Ì¨µÄÒ»Ì×ÔËάÖÎÀí½â¾ö¹æ»®¡£
2021Äê03ÔÂ31ÈÕ£¬VMware¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËVMware vRealize Operations ÖеÄÒ»¸öSSRF·ì϶ºÍÒ»¸öËÁÒâÎļþÉÏ´«·ì϶£¨·ì϶׷×ÙΪCVE-2021-21975ºÍCVE-2021-21983£©¡£
vRealize Operations·þÎñÆ÷¶ËÒªÇóαÔ죨CVE-2021-21975£©
vRealize Operations Manager APIÖдæÔÚÒ»¸ö·þÎñÆ÷¶ËÒªÇóαÔì·ì϶£¬ÆäCVSSÆÀ·ÖΪ8.6¡£ÓµÓÐvRealize Operations Manager APIÍøÂç½Ó¼ûȨÏÞ¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶ִÐзþÎñÆ÷¶ËÒªÇóαÔì¹¥»÷£¬ÒÔÇÔÈ¡ÖÎÀíԱʹ´¦¡£
Realize OperationsËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2021-21983£©
vRealize Operations Manager APIÖдæÔÚÒ»¸öËÁÒâÎļþÉÏ´«·ì϶£¬ÆäCVSSÆÀ·ÖΪ7.2¡£ÓµÓÐÍøÂç½Ó¼ûvRealize Operations Manager APIȨÏ޵ľ¹ýÑéÖ¤µÄ¹¥»÷ÕßÄܹ»½«ËÁÒâÎļþÉÏ´«µ½ÏµÍ³ÉÏ¡£
Ó°ÏìÁìÓò
VMware vRealize operations manager£º 8.3.0¡¢8.2.0¡¢8.1.1¡¢8.1.0¡¢8.0.1¡¢8.0.0¡¢7.5.0
VMware cloud foundation£¨vROps£©: 4.x¡¢3.x
vRealize Suite Lifecycle Manager (vROps)£º8.x
0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶PoCÒѹ«¿ª£¬½¨Òé²Î¿¼¹Ù·½²¼¸æÊµÊ±Éý¼¶»ò×°ÖÃÏàÓ¦²¹¶¡¡£
ÏÂÔØÁ´½Ó£º
https://kb.vmware.com/s/article/83210
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0004.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21975
https://www.bleepingcomputer.com/news/security/vmware-fixes-bug-allowing-attackers-to-steal-admin-credentials/
0x04 ¹¦·òÏß
2021-03-30 VMware°ä²¼°²È«²¼¸æ
2021-03-31 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ