CVE Vulnerabilities

CVE-2021-21993

Server-Side Request Forgery (SSRF)

Published: Sep 23, 2021 | Modified: Sep 27, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to information disclosure.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Cloud_foundation Vmware 3.0 (including) 5.0 (excluding)
Vcenter_server Vmware 6.5 (including) 6.5 (including)
Vcenter_server Vmware 6.7 (including) 6.7 (including)
Vcenter_server Vmware 7.0 (including) 7.0 (including)

References