MEDIUM

CVE-2021-22017

Vmware Vcenter Server 2021-09-23 CVSS v3.1
CVSS
5.3
KEV

Description

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

Summary dbcve.org

Rhttproxy in vCenter Server has improper URI normalization, allowing attackers with network access to port 443 to bypass the proxy and access internal endpoints that should be protected.

Mitigation

Apply VMware's security patch for CVE-2021-22017 to vCenter Server and verify proxy behavior functions correctly post-patch.

Patch Commit

EPSS Score

49.18%
Probability of exploitation in next 30 days
98.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE