CVE-2021-21993
Summary
| CVE | CVE-2021-21993 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-23 12:15:00 UTC |
| Updated | 2021-09-27 18:53:00 UTC |
| Description | The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to information disclosure. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 216265 VMware vCenter Server 7.0 Update 7.0 U2c (VMSA-2021-0020)
- 216266 VMware vCenter Server 6.7 Update 6.7 U3o (VMSA-2021-0020)
- 216267 VMware vCenter Server 6.5 Update 6.5 U3q (VMSA-2021-0020)