VMware ¶à¸ö²úÆ· Log4j2 RCE£¨CVE-2021-44228£©Î£¼¶Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2021-12-13Îó²î˵Ã÷
Apache Log4j2ÊÇÒ»¿îApacheÈí¼þ»ù½ð»áµÄ¿ªÔ´»ù´¡¿ò¼Ü,ÓÃÓÚJavaÈÕÖ¾¼Í¼µÄ¹¤¾ß¡£ÈÕÖ¾¼Í¼Ö÷ÒªÓÃÀ´¼àÊÓ´úÂëÖбäÁ¿µÄת±äÇéÐΣ¬ÖÜÆÚÐԵļͼµ½ÎļþÖй©ÆäËûÓ¦ÓþÙÐÐͳ¼ÆÆÊÎöÊÂÇ飻¸ú×Ù´úÂëÔËÐÐʱ¹ì¼££¬×÷ΪÈÕºóÉó¼ÆµÄÒÀ¾Ý£»¼ÌÐø¼¯³É¿ª·¢ÇéÐÎÖеĵ÷ÊÔÆ÷µÄ×÷Óã¬ÏòÎļþ»ò¿ØÖÆ̨´òÓ¡´úÂëµÄµ÷ÊÔÐÅÏ¢¡£ÆäÔÚJAVAÉú̬ÇéÐÎÖÐÓ¦Óü«ÆäÆÕ±é,Ó°ÏìÖØ´ó¡£
¿ËÈÕ, Apache Log4j2 ±»±¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©£¬¸ÃÎó²îÒ»µ©±»¹¥»÷ÕßʹÓûáÔì³ÉÑÏÖØΣº¦¡£¸ÃÎó²îµÄ´¥·¢µãÔÚÓÚʹÓÃorg.apache.logging.log4j.Logger¾ÙÐÐlog»òerrorµÈ¼Í¼²Ù×÷ʱδ¶ÔÈÕÖ¾messageÐÅÏ¢¾ÙÐÐÓÐÓüì²é,´Ó¶øµ¼ÖÂÎó²î±¬·¢¡£
VMwareÖÚ¶à²úÆ·ÊÜ´ËÎó²îÓ°Ïì,ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabµÚһʱ¼ä²âÊÔ²¢È·ÈÏVMware vCenter6.5¡¢VMware vCenter6.7¡¢VMware vCenter7.0¡¢VMware NSXÊÜ´ËÎó²îµÄÓ°Ïì,¿ÉÔÚδÊÚȨµÄÇéÐÎϵִïÔ¶³ÌÏÂÁîÖ´ÐеÄЧ¹û¡£
Ó°Ïì°æ±¾
VMware¹Ù·½Ðû²¼ÊÜ´ËÎó²îÓ°ÏìµÄ²úÆ·ÁбíÈçÏÂËùʾ:
VMware Horizon
VMware vCenter Server
VMware HCX
VMware NSX-T Data Center
VMware Unified Access Gateway
VMware WorkspaceOne Access
VMware Identity Manager
VMware vRealize Operations
VMware vRealize Operations Cloud Proxy
VMware vRealize Log Insight
VMware vRealize Automation
VMware vRealize Lifecycle Manager
VMware Telco Cloud Automation
VMware Site Recovery Manager
VMware Carbon Black Cloud Workload Appliance
VMware Carbon Black EDR Server
VMware Tanzu GemFire
VMware Tanzu Greenplum
VMware Tanzu Operations Manager
VMware Tanzu Application Service for VMs
VMware Tanzu Kubernetes Grid Integrated Edition
VMware Tanzu Observability by Wavefront Nozzle
Healthwatch for Tanzu Application Service
Spring Cloud Services for VMware Tanzu
Spring Cloud Gateway for VMware Tanzu
Spring Cloud Gateway for Kubernetes
API Portal for VMware Tanzu
Single Sign-On for VMware Tanzu Application Service
App Metrics
VMware vCenter Cloud Gateway
VMware Tanzu SQL with MySQL for VMs
VMware vRealize Orchestrator
VMware Cloud Foundation
Îó²îÐÞ¸´
¼øÓÚÒѾ·¢Ã÷Õë¶ÔVMwarevCenter µÈÓ¦ÓõÄÔÚÒ°¹¥»÷ʹÓÃ,ÏÂÃæ¸ø³öVMware¹Ù·½µÄÇ徲ͨ¸æÁ´½Ó:
https://www.vmware.com/security/advisories/VMSA-2021-0028.html
Õë¶ÔLog4j2Îó²î£¬VMwareÔÝʱֻ¸ø³öÁËÎó²î»º½â²½·¥,²¢Î´Ðû²¼Çå¾²²¹¶¡,¿ÉÒԲο¼½¨Òé¶ÔÏìӦϵͳ¾ÙÐмӹ̡£»¹Çë¼ÌÐø¹Ø×¢Æä²¹¶¡¸üС£