MEDIUM
CVE-2021-22017
CVSS
5.3
KEV
Description
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.
Summary dbcve.org
Rhttproxy in vCenter Server has improper URI normalization, allowing attackers with network access to port 443 to bypass the proxy and access internal endpoints that should be protected.
Mitigation
Apply VMware's security patch for CVE-2021-22017 to vCenter Server and verify proxy behavior functions correctly post-patch.
EPSS Score
49.18%
Probability of exploitation in next 30 days
98.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.