VMware vRealize SSRFÎó²î£¨CVE-2021-21975£©

Ðû²¼Ê±¼ä 2021-03-31

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-21975

ʱ    ¼ä

2021-03-31

Àà   ÐÍ

 SSRF

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

 

Vmware vRealize Operations ManagerÊÇÕë¶ÔvmwareÐéÄ⻯ƽ̨µÄÒ»Ì×ÔËάÖÎÃ÷È·¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£

2021Äê03ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬VMware¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬¹ûÕæÁËVMware vRealize Operations ÖеÄÒ»¸öSSRFÎó²îºÍÒ»¸öí§ÒâÎļþÉÏ´«Îó²î£¨Îó²î×·×ÙΪCVE-2021-21975ºÍCVE-2021-21983£©¡£¡£¡£¡£¡£¡£¡£

vRealize OperationsЧÀÍÆ÷¶ËÇëÇóαÔ죨CVE-2021-21975£©

vRealize Operations Manager APIÖб£´æÒ»¸öЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ8.6¡£¡£¡£¡£¡£¡£¡£¾ßÓÐvRealize Operations Manager APIÍøÂç»á¼ûȨÏÞ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÖ´ÐÐЧÀÍÆ÷¶ËÇëÇóαÔì¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡ÖÎÀíԱƾ֤¡£¡£¡£¡£¡£¡£¡£

 

Realize Operationsí§ÒâÎļþÉÏ´«Îó²î£¨CVE-2021-21983£©

vRealize Operations Manager APIÖб£´æÒ»¸öí§ÒâÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2¡£¡£¡£¡£¡£¡£¡£¾ßÓÐÍøÂç»á¼ûvRealize Operations Manager APIȨÏ޵ľ­ÓÉÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ½«í§ÒâÎļþÉÏ´«µ½ÏµÍ³ÉÏ¡£¡£¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

VMware vRealize operations manager£º 8.3.0¡¢8.2.0¡¢8.1.1¡¢8.1.0¡¢8.0.1¡¢8.0.0¡¢7.5.0

VMware cloud foundation£¨vROps£©: 4.x¡¢3.x

vRealize Suite Lifecycle Manager (vROps)£º8.x

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îPoCÒѹûÕæ£¬£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼¹Ù·½Í¨¸æÊµÊ±Éý¼¶»ò×°ÖÃÏìÓ¦²¹¶¡¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://kb.vmware.com/s/article/83210

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0004.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21975

https://www.bleepingcomputer.com/news/security/vmware-fixes-bug-allowing-attackers-to-steal-admin-credentials/


0x04 ʱ¼äÏß

2021-03-30  VMwareÐû²¼Ç徲ͨ¸æ

2021-03-31  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png