VMware ¶à¸ö²úÎï Log4j2 RCE£¨CVE-2021-44228£©Î£¼¶Â©¶´Í¨¸æ

Ðû²¼Ê±¼ä 2021-12-13

©¶´ËµÃ÷ 


Apache Log4j2ÊÇÒ»¿îApacheÈí¼þ»ù½ð»áµÄ¿ªÔ´»ù´¡¿ò¼Ü,ÓÃÓÚJavaÈÕÖ¾¼Ç¼µÄ¹¤¾ß ¡£ÈÕÖ¾¼Ç¼Ö÷ÒªÓÃÀ´¼àÊÓ´úÂëÖбäÁ¿µÄ±ä»¯Çé¿ö£¬ÖÜÆÚÐԵļǼµ½ÎļþÖй©ÆäËûÓ¦ÓýøÐÐͳ¼Æ·ÖÎöÊÂÇ飻¸ú×Ù´úÂëÔËÐÐʱ¹ì¼££¬×÷ΪÈÕºóÉó¼ÆµÄÒÀ¾Ý£»¼Ì³Ð¼¯³É¿ª·¢»·¾³Öеĵ÷ÊÔÆ÷µÄ×÷Óã¬ÏòÎļþ»ò¿ØÖÆ̨´òÓ¡´úÂëµÄµ÷ÊÔÐÅÏ¢ ¡£ÆäÔÚJAVAÉú̬»·¾³ÖÐÓ¦Óü«Æä¹ã·º,Ó°Ïì¾Þ´ó ¡£


½üÈÕ, Apache Log4j2 ±»±¬´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-44228£©£¬¸Ã©¶´Ò»µ©±»¹¥»÷ÕßÀûÓûáÔì³ÉÑÏÖØΣº¦ ¡£¸Ã©¶´µÄ´¥·¢µãÔÚÓÚÀûÓÃorg.apache.logging.log4j.Logger½øÐÐlog»òerrorµÈ¼Ç¼²Ù×÷ʱδ¶ÔÈÕÖ¾messageÐÅÏ¢½øÐÐÓÐЧ¼ì²é,´Ó¶øµ¼Ö©¶´·¢Éú ¡£


VMwareÖÚ¶à²úÎïÊÜ´Ë©¶´Ó°Ïì,¶«É­Æ½Ì¨ADLabµÚһʱ¼ä²âÊÔ²¢È·ÈÏVMware vCenter6.5¡¢VMware vCenter6.7¡¢VMware vCenter7.0¡¢VMware NSXÊÜ´Ë©¶´µÄÓ°Ïì,¿ÉÔÚδÊÚȨµÄÇé¿öϵ½´ïÔ¶³ÌÃüÁîÖ´ÐеÄЧ¹û ¡£


©¶´ËµÃ÷.png


©¶´ËµÃ÷Ó°Ïì.png


 Ó°Ïì°æ±¾ 


VMware¹Ù·½Ðû²¼ÊÜ´Ë©¶´Ó°ÏìµÄ²úÎïÁбíÈçÏÂËùʾ:

VMware Horizon

VMware vCenter Server

VMware HCX

VMware NSX-T Data Center

VMware Unified Access Gateway

VMware WorkspaceOne Access

VMware Identity Manager

VMware vRealize Operations

VMware vRealize Operations Cloud Proxy

VMware vRealize Log Insight

VMware vRealize Automation

VMware vRealize Lifecycle Manager

VMware Telco Cloud Automation

VMware Site Recovery Manager

VMware Carbon Black Cloud Workload Appliance

VMware Carbon Black EDR Server

VMware Tanzu GemFire

VMware Tanzu Greenplum

VMware Tanzu Operations Manager

VMware Tanzu Application Service for VMs

VMware Tanzu Kubernetes Grid Integrated Edition

VMware Tanzu Observability by Wavefront Nozzle

Healthwatch for Tanzu Application Service

Spring Cloud Services for VMware Tanzu

Spring Cloud Gateway for VMware Tanzu

Spring Cloud Gateway for Kubernetes

API Portal for VMware Tanzu

Single Sign-On for VMware Tanzu Application Service

App Metrics

VMware vCenter Cloud Gateway

VMware Tanzu SQL with MySQL for VMs

VMware vRealize Orchestrator

VMware Cloud Foundation

 

 Â©¶´ÐÞ¸´ 


¼øÓÚÒѾ­·¢ÏÖÕë¶ÔVMwarevCenter µÈÓ¦ÓõÄÔÚÒ°¹¥»÷ÀûÓÃ,ÏÂÃæ¸ø³öVMware¹Ù·½µÄÄþ¾²Í¨¸æÁ´½Ó:

https://www.vmware.com/security/advisories/VMSA-2021-0028.html


Õë¶ÔLog4j2©¶´£¬VMwareÔÝʱֻ¸ø³öÁË©¶´»º½â´ëÊ©,²¢Î´Ðû²¼Äþ¾²²¹¶¡,¿ÉÒԲο¼½¨Òé¶ÔÏàӦϵͳ½øÐÐ¼Ó¹Ì ¡£»¹Çë¼ÌÐø¹Ø×¢Æä²¹¶¡¸üР¡£