The vSphere Web Client (FLEX/Flash) contains an SSRF ...
Critical severity
Unreviewed
Published
Nov 25, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Nov 24, 2021
Published to the GitHub Advisory Database
Nov 25, 2021
Last updated
Feb 1, 2023
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
References