VMware ¶à¸ö²úÆ· Log4j2 RCE£¨CVE-2021-44228£©Î£¼¶Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2021-12-13

Îó²î˵Ã÷ 


Apache Log4j2ÊÇÒ»¿îApacheÈí¼þ»ù½ð»áµÄ¿ªÔ´»ù´¡¿ò¼Ü,ÓÃÓÚJavaÈÕÖ¾¼Í¼µÄ¹¤¾ß ¡£ÈÕÖ¾¼Í¼Ö÷ÒªÓÃÀ´¼àÊÓ´úÂëÖбäÁ¿µÄת±äÇéÐΣ¬ÖÜÆÚÐԵļͼµ½ÎļþÖй©ÆäËûÓ¦ÓþÙÐÐͳ¼ÆÆÊÎöÊÂÇ飻¸ú×Ù´úÂëÔËÐÐʱ¹ì¼££¬×÷ΪÈÕºóÉó¼ÆµÄÒÀ¾Ý£»¼ÌÐø¼¯³É¿ª·¢ÇéÐÎÖеĵ÷ÊÔÆ÷µÄ×÷Óã¬ÏòÎļþ»ò¿ØÖÆ̨´òÓ¡´úÂëµÄµ÷ÊÔÐÅÏ¢ ¡£ÆäÔÚJAVAÉú̬ÇéÐÎÖÐÓ¦Óü«ÆäÆÕ±é,Ó°ÏìÖØ´ó ¡£


¿ËÈÕ, Apache Log4j2 ±»±¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©£¬¸ÃÎó²îÒ»µ©±»¹¥»÷ÕßʹÓûáÔì³ÉÑÏÖØΣº¦ ¡£¸ÃÎó²îµÄ´¥·¢µãÔÚÓÚʹÓÃorg.apache.logging.log4j.Logger¾ÙÐÐlog»òerrorµÈ¼Í¼²Ù×÷ʱδ¶ÔÈÕÖ¾messageÐÅÏ¢¾ÙÐÐÓÐÓüì²é,´Ó¶øµ¼ÖÂÎó²î±¬·¢ ¡£


VMwareÖÚ¶à²úÆ·ÊÜ´ËÎó²îÓ°Ïì,ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabµÚһʱ¼ä²âÊÔ²¢È·ÈÏVMware vCenter6.5¡¢VMware vCenter6.7¡¢VMware vCenter7.0¡¢VMware NSXÊÜ´ËÎó²îµÄÓ°Ïì,¿ÉÔÚδÊÚȨµÄÇéÐÎϵִïÔ¶³ÌÏÂÁîÖ´ÐеÄЧ¹û ¡£


Îó²î˵Ã÷.png


Îó²î˵Ã÷Ó°Ïì.png


 Ó°Ïì°æ±¾ 


VMware¹Ù·½Ðû²¼ÊÜ´ËÎó²îÓ°ÏìµÄ²úÆ·ÁбíÈçÏÂËùʾ:

VMware Horizon

VMware vCenter Server

VMware HCX

VMware NSX-T Data Center

VMware Unified Access Gateway

VMware WorkspaceOne Access

VMware Identity Manager

VMware vRealize Operations

VMware vRealize Operations Cloud Proxy

VMware vRealize Log Insight

VMware vRealize Automation

VMware vRealize Lifecycle Manager

VMware Telco Cloud Automation

VMware Site Recovery Manager

VMware Carbon Black Cloud Workload Appliance

VMware Carbon Black EDR Server

VMware Tanzu GemFire

VMware Tanzu Greenplum

VMware Tanzu Operations Manager

VMware Tanzu Application Service for VMs

VMware Tanzu Kubernetes Grid Integrated Edition

VMware Tanzu Observability by Wavefront Nozzle

Healthwatch for Tanzu Application Service

Spring Cloud Services for VMware Tanzu

Spring Cloud Gateway for VMware Tanzu

Spring Cloud Gateway for Kubernetes

API Portal for VMware Tanzu

Single Sign-On for VMware Tanzu Application Service

App Metrics

VMware vCenter Cloud Gateway

VMware Tanzu SQL with MySQL for VMs

VMware vRealize Orchestrator

VMware Cloud Foundation

 

 Îó²îÐÞ¸´ 


¼øÓÚÒѾ­·¢Ã÷Õë¶ÔVMwarevCenter µÈÓ¦ÓõÄÔÚÒ°¹¥»÷ʹÓÃ,ÏÂÃæ¸ø³öVMware¹Ù·½µÄÇ徲ͨ¸æÁ´½Ó:

https://www.vmware.com/security/advisories/VMSA-2021-0028.html


Õë¶ÔLog4j2Îó²î£¬VMwareÔÝʱֻ¸ø³öÁËÎó²î»º½â²½·¥,²¢Î´Ðû²¼Çå¾²²¹¶¡,¿ÉÒԲο¼½¨Òé¶ÔÏìӦϵͳ¾ÙÐÐ¼Ó¹Ì ¡£»¹Çë¼ÌÐø¹Ø×¢Æä²¹¶¡¸üР¡£