VMware vRealize SSRF·ì϶£¨CVE-2021-21975£©

°ä²¼¹¦·ò 2021-03-31

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-21975

ʱ    ¼ä

2021-03-31

Àà   ÐÍ

 SSRF

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

Vmware vRealize Operations ManagerÊÇÕë¶ÔvmwareÐé¹¹»¯Æ½Ì¨µÄÒ»Ì×ÔËάÖÎÀí½â¾ö¹æ»®¡£

2021Äê03ÔÂ31ÈÕ£¬VMware¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËVMware vRealize Operations ÖеÄÒ»¸öSSRF·ì϶ºÍÒ»¸öËÁÒâÎļþÉÏ´«·ì϶£¨·ì϶׷×ÙΪCVE-2021-21975ºÍCVE-2021-21983£©¡£

vRealize Operations·þÎñÆ÷¶ËÒªÇóαÔ죨CVE-2021-21975£©

vRealize Operations Manager APIÖдæÔÚÒ»¸ö·þÎñÆ÷¶ËÒªÇóαÔì·ì϶£¬ÆäCVSSÆÀ·ÖΪ8.6¡£ÓµÓÐvRealize Operations Manager APIÍøÂç½Ó¼ûȨÏÞ¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶ִÐзþÎñÆ÷¶ËÒªÇóαÔì¹¥»÷£¬ÒÔÇÔÈ¡ÖÎÀíԱʹ´¦¡£

 

Realize OperationsËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2021-21983£©

vRealize Operations Manager APIÖдæÔÚÒ»¸öËÁÒâÎļþÉÏ´«·ì϶£¬ÆäCVSSÆÀ·ÖΪ7.2¡£ÓµÓÐÍøÂç½Ó¼ûvRealize Operations Manager APIȨÏ޵ľ­¹ýÑéÖ¤µÄ¹¥»÷ÕßÄܹ»½«ËÁÒâÎļþÉÏ´«µ½ÏµÍ³ÉÏ¡£

 

Ó°ÏìÁìÓò

VMware vRealize operations manager£º 8.3.0¡¢8.2.0¡¢8.1.1¡¢8.1.0¡¢8.0.1¡¢8.0.0¡¢7.5.0

VMware cloud foundation£¨vROps£©: 4.x¡¢3.x

vRealize Suite Lifecycle Manager (vROps)£º8.x

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶PoCÒѹ«¿ª£¬½¨Òé²Î¿¼¹Ù·½²¼¸æÊµÊ±Éý¼¶»ò×°ÖÃÏàÓ¦²¹¶¡¡£

ÏÂÔØÁ´½Ó£º

https://kb.vmware.com/s/article/83210

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0004.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21975

https://www.bleepingcomputer.com/news/security/vmware-fixes-bug-allowing-attackers-to-steal-admin-credentials/


0x04 ¹¦·òÏß

2021-03-30  VMware°ä²¼°²È«²¼¸æ

2021-03-31  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png