¡¾Íþвͨ¸æ¡¿VMware vCenter Server ¶à¸ö¸ßΣÎó²îͨ¸æ
2021-09-22
Ò». Îó²î¸ÅÊö
9ÔÂ22ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½VMware ¹Ù·½Ðû²¼Ç徲ͨ¸æÅû¶ÁËVMware vCenter ServerÖеĶà¸öÎó²î£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÔì³ÉÐÅϢй¶¡¢È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´Ðеȡ£ÏÖÔÚ¹Ù·½ÒѸüа汾ÐÞ¸´£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
vCenter ServerÊÇVMware¹«Ë¾µÄÒ»ÖÖ·þÎñÆ÷ÖÎÃ÷È·¾ö¼Æ»®£¬¿É×ÊÖúITÖÎÀíԱͨ¹ýµ¥¸ö¿ØÖÆÌ¨ÖÎÀíÆóÒµÇéÐÎÖеÄÐéÄâ»úºÍÐéÄ⻯Ö÷»ú¡£
²Î¿¼Á´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
¶þ. ÖØµãÎó²î¼òÊö
vCenter Server í§ÒâÎļþÉÏ´«Îó²î (CVE-2021-22005)£º
δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýAnalytics·þÎñÉÏ´«ÌØÖƵÄÎļþµ½vCenter Server µÄ443¶Ë¿Ú£¬´Ó¶øÔÚÄ¿µÄϵͳÉÏÒÔ¸ÃÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂ룬CVSSÆÀ·Ö£º9.8¡£
vCenter Server ȨÏÞÌáÉýÎó²î (CVE-2021-21991)£º
ÓÉÓÚvCenter Server´¦Öóͷ£»á»°ÁîÅÆµÄ·½·¨²»×¼È·£¬·ÇÖÎÀíÓû§»á¼ûȨÏ޵Ĺ¥»÷ÕßʹÓøÃÎó²î¿É½«È¨ÏÞÌáÉýµ½ vSphere Client (HTML5) »ò vCenter Server vSphere Web Client (FLEX/Flash)µÄÖÎÀíԱȨÏÞ£¬CVSSÆÀ·Ö£º8.8¡£
vCenter Server ·´ÏòÊðÀíÈÆ¹ýÎó²î (CVE-2021-22006)£º
ÓÉÓڶ˵㴦Öóͷ£URLµÄ·½·¨Òì³££¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ývCenter ServerµÄ443¶Ë¿Ú»á¼ûÊÜÏÞÖÆµÄ¶Ëµã£¬CVSSÆÀ·Ö£º8.3¡£
vCenter Server δ¾Éí·ÝÑéÖ¤µÄ API ¶ËµãÎó²î (CVE-2021-22011)£º
ÓÉÓÚvCenter Server ÄÚÈÝ¿âÖаüÀ¨Ò»¸öδ¾Éí·ÝÑéÖ¤µÄ API ¶ËµãÎó²î£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐ VM ÍøÂçÉèÖòÙ×÷£¬CVSSÆÀ·Ö£º8.1¡£
vCenter ServerÍâµØÌáȨÎó²î (CVE-2021-22015)£º
ÓÉÓÚ¶ÔÎļþºÍĿ¼ȨÏÞ¿ØÖƲ»µ±£¬µ¼ÖÂvCenter Server °üÀ¨¶à¸öÍâµØÌáȨÎó²î£¬¾ßÓзÇÖÎÀíÓû§»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉʹÓôËÀàÎó²îÔÚ vCenter Server Appliance ÉϽ«ÏµÍ³È¨ÏÞÌáÉýΪ root£¬CVSSÆÀ·Ö£º7.8¡£
Èý. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
VMware vCenter Server 7.0ϵÁÐ < 7.0 U2c
VMware vCenter Server 6.7ϵÁÐ < 6.7 U3o
VMware vCenter Server 6.5ϵÁÐ < 6.5 U3q
Cloud Foundation (vCenter Server) 4.xϵÁÐ < 4.3
Cloud Foundation (vCenter Server) 3.xϵÁÐ < 3.10.2.2
²»ÊÜÓ°Ïì°æ±¾
VMware vCenter Server = 7.0 U2c
VMware vCenter Server = 6.7 U3o
VMware vCenter Server = 6.5 U3q
Cloud Foundation (vCenter Server) = 4.3
Cloud Foundation (vCenter Server) = 3.10.2.2
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¶ÔÓ¦²úÆ·°æ±¾µÄÏÂÔØÁ´½Ó¼°ÎĵµÈçÏ£º
|
²úÆ·°æ±¾ |
ÏÂÔØÁ´½Ó |
²Ù×÷Îĵµ |
|
vCenter Server 7.0 U2d |
https://customerconnect.vmware.com/downloads/details?downloadGroup=VC70U2D&productId=974&rPId=74352 |
https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-vcenter-server-70u2d-release-notes.html |
|
vCenter Server 6.7 U3o |
https://customerconnect.vmware.com/downloads/details?downloadGroup=VC67U3O&productId=742&rPId=73667 |
https://docs.vmware.com/en/VMware-vSphere/6.7/rn/vsphere-vcenter-server-67u3o-release-notes.html |
|
vCenter Server 6.5 U3q |
https://customerconnect.vmware.com/downloads/details?downloadGroup=VC65U3Q&productId=614&rPId=74057 |
https://docs.vmware.com/en/VMware-vSphere/6.5/rn/vsphere-vcenter-server-65u3q-release-notes.html |
|
VMware vCloud Foundation 4.3.1 |
https://docs.vmware.com/en/VMware-Cloud-Foundation/4.3.1/rn/VMware-Cloud-Foundation-431-Release-Notes.html |
|
|
VMware vCloud Foundation 3.10.2.2 |
https://docs.vmware.com/en/VMware-Cloud-Foundation/3.10.2/rn/VMware-Cloud-Foundation-3102-Release-Notes.html |
|
³£¼ûÎÊÌâ¿É²Î¿¼£ºhttps://via.vmw.com/vmsa-2021-0020-faq
4.2 ÔÝʱ·À»¤²½·¥£º
Õë¶ÔVMware vCenter Server í§ÒâÎļþÉÏ´«Îó²î£¨CVE-2021-22005£©£¬¿É²Î¿¼¹Ù·½¸ø³öµÄ²½·¥¾ÙÐÐÔÝʱ»º½â£ºhttps://kb.vmware.com/s/article/85717
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







