The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to information disclosure.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2021-0020.html | Patch Vendor Advisory | 
| https://www.vmware.com/security/advisories/VMSA-2021-0020.html | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 05:49
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.vmware.com/security/advisories/VMSA-2021-0020.html - Patch, Vendor Advisory | 
27 Sep 2021, 18:53
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-918 | |
| CVSS | v2 : v3 : | v2 : 4.0 v3 : 6.5 | 
| CPE | cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:* cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:* | |
| References | (MISC) https://www.vmware.com/security/advisories/VMSA-2021-0020.html - Patch, Vendor Advisory | 
23 Sep 2021, 13:00
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2021-09-23 12:15
Updated : 2024-11-21 05:49
NVD link : CVE-2021-21993
Mitre link : CVE-2021-21993
CVE.ORG link : CVE-2021-21993
JSON object : View
Products Affected
                vmware
- vcenter_server
- cloud_foundation
CWE
                
                    
                        
                        CWE-918
                        
            Server-Side Request Forgery (SSRF)
