Executive brief
The vSphere Client (HTML5) contains a Server Side Request Forgery (SSRF) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 can exploit this by sending a POST request, potentially leading to information disclosure.
Affected products
- VMware vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n
- VMware Cloud Foundation 4.x before 4.2, 3.x before 3.10.1.2
Timeline
- 2021-02-23: disclosed: Initial vendor advisory VMSA-2021-0002 published
- 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-07: exploited: Confirmed exploited in the wild per CISA KEV entry