CVE-2021-21973
Description
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Summary dbcve.org
CVE-2021-21973 is an SSRF (Server Side Request Forgery) vulnerability in the vSphere Client (HTML5) stemming from improper validation of URLs within a vCenter Server plugin. An unauthenticated attacker with network access to port 443 can send crafted POST requests to trigger the SSRF, potentially disclosing sensitive information from internal resources or the server itself.
Mitigation
Apply the vendor-supplied patches: upgrade vCenter Server to 7.0 U1c or later, 6.7 U3l or later, 6.5 U3n or later; upgrade Cloud Foundation to 4.2 or later or 3.10.1.2 or later. As an interim control, restrict network access to port 443 to trusted sources only.