¡¾Íþвͨ¸æ¡¿VMware ¶à¸ö²úÆ·±£´æ?Log4j2Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©Í¨¸æ
2021-12-14
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½VMware Ðû²¼Ç徲ͨ¸æ£¬VMwareµÄÖÚ¶à²úÆ·ÊÜApache Log4j2Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©µÄÓ°Ïì¡£ÓÉÓÚApache Log4j2ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾ÝÇëÇó°ü£¬¿ÉÔÚÊÜÓ°ÏìµÄ VMware ²úÆ·ÖÐÖ´ÐÐí§Òâ´úÂë¡£Îó²îPoCÒѹûÕæ£¬ÇÒ·¢Ã÷ÔÚҰʹÓ㬽¨ÒéÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐÐÅŲéÓë·À»¤¡£
²Î¿¼Á´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2021-0028.html
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì²úÆ·£¨¸üÐÂÖУ©£º
VMware Horizon
VMware vCenter Server
VMware HCX
VMware NSX-T Data Center
VMware Unified Access Gateway
VMware WorkspaceOne Access
VMware Identity Manager
VMware vRealize Operations
VMware vRealize Operations Cloud Proxy
VMware vRealize Log Insight
VMware vRealize Automation
VMware vRealize Lifecycle Manager
VMware Telco Cloud Automation
VMware Site Recovery Manager, vSphere Replication
VMware Carbon Black Cloud Workload Appliance
VMware Carbon Black EDR Server
VMware Tanzu GemFire
VMware Tanzu Greenplum
VMware Tanzu Operations Manager
VMware Tanzu Application Service for VMs
VMware Tanzu Kubernetes Grid Integrated Edition
VMware Tanzu Observability by Wavefront Nozzle
Healthwatch for Tanzu Application Service
Spring Cloud Services for VMware Tanzu
Spring Cloud Gateway for VMware Tanzu
Spring Cloud Gateway for Kubernetes
API Portal for VMware Tanzu
Single Sign-On for VMware Tanzu Application Service
App Metrics
VMware vCenter Cloud Gateway
VMware Tanzu SQL with MySQL for VMs
VMware vRealize Orchestrator
VMware Cloud Foundation
VMware Workspace ONE Access Connector
VMware Horizon DaaS
VMware Horizon Cloud Connector
VMware NSX Data Center for vSphere
VMware AppDefense Appliance
²»ÊÜÓ°Ïì²úÆ·£¨¸üÐÂÖУ©£º
VMware vSphere ESXi
VMware vCloud Director
VMware vCloud Availability
VMware NSX Advanced Load Balancer (Avi)
VMware Software-Defined WAN (SD-WAN)
VMware Workspace ONE Assist
VMware RemoteHelp
VMware vCloud Usage Meter
VMware Tanzu Scheduler
VMware Tanzu Kubernetes Grid
SaltStack
²Î¿¼Á´½Ó£ºhttps://kb.vmware.com/s/article/87068
Èý. Îó²î·À»¤
3.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÕë¶ÔÒÔϲúÆ·Ðû²¼ÁËа汾ÐÞ¸´¸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¶ÔÓ¦²úÆ·°æ±¾µÄÏÂÔØÁ´½Ó¼°ÎĵµÈçÏ£º
|
²úÆ·°æ±¾ |
ÏÂÔØÁ´½Ó |
²Ù×÷Îĵµ |
|
VMware Tanzu Operations Manager href="https://network.pivotal.io/products/ops-manager/" 2.10.23 |
https://network.pivotal.io/products/ops-manager/ |
https://docs.pivotal.io/ops-manager/2-10/release-notes.html#2-10-23 |
|
VMware Tanzu Application Service 2.12.3¡¢2.11.10¡¢2.10.22¡¢2.7.42 |
https://network.pivotal.io/products/elastic-runtime |
https://docs.pivotal.io/application-service/2-12/release-notes/runtime-rn.html#2.12.3 https://docs.pivotal.io/application-service/2-11/release-notes/runtime-rn.html#2.11.10 https://docs.pivotal.io/application-service/2-10/release-notes/runtime-rn.html#2.10.22 https://docs.pivotal.io/application-service/2-7/release-notes/runtime-rn.html#2.7.42) |
|
VMware Tanzu Observability by Wavefront Nozzle href="https://network.pivotal.io/products/wavefront-nozzle" 3.0.3 |
https://network.pivotal.io/products/wavefront-nozzle |
|
|
Healthwatch for Tanzu Application Service href="https://network.pivotal.io/products/p-healthwatch" 2.1.7, 1.8.6 |
https://network.pivotal.io/products/p-healthwatch |
|
|
App Metrics href="https://network.pivotal.io/products/apm" 2.1.1 |
https://network.pivotal.io/products/apm |
|
|
VMware Horizon Cloud Connector href="#product_downloads" 2.1.1 |
https://customerconnect.vmware.com/downloads/details?downloadGroup=HCS-CC-210&productId=716&rPId=79131#product_downloads |
|
|
VMware Carbon Black EDR Server 7.6.0 |
https://community.carbonblack.com/t5/Endpoint-Detection-and-Response/VMware-Carbon-Black-EDR-Announcing-General-Availability-of-EDR/td-p/109189 |
|
Èý.2 ÔÝʱ·À»¤²½·¥£º
1.ÈôÓªÒµÇéÐÎÔÊÐí£¬¿ÉʹÓð×Ãûµ¥ÏÞÖÆweb¶Ë¿Ú»á¼û·½·¨À´½µµÍΣº¦
2.¿Í»§¿Éƾ֤×ÔÉí²úÆ·ÍŽáÏÂÁвο¼Á´½Ó½ÓÄÉÔÝʱ·À»¤¡£
|
²úÆ·°æ±¾ |
²Î¿¼Á´½Ó |
|
VMware Horizon 8.x, 7.x |
https://kb.vmware.com/s/article/87073 |
|
VMware vCenter Server 7.x, 6.x |
https://kb.vmware.com/s/article/87081?lang=en_US |
|
VMware HCX 4.x, 3.x |
https://kb.vmware.com/s/article/86169 |
|
VMware NSX-T Data Center 3.x, 2.x |
https://kb.vmware.com/s/article/87086 |
|
VMware Unified Access Gateway 21.x, 20.x, 3.x |
https://kb.vmware.com/s/article/87092 |
|
VMware Workspace ONE Access 21.x, 20.10.x |
https://kb.vmware.com/s/article/87090 |
|
VMware Identity Manager 3.3.x |
https://kb.vmware.com/s/article/87093 |
|
VMware vRealize Operations 8.x |
https://kb.vmware.com/s/article/87076 |
|
VMware vRealize Operations Cloud Proxy Any |
https://kb.vmware.com/s/article/87080 |
|
VMware vRealize Log Insight 8.x |
https://kb.vmware.com/s/article/87089?lang=en_US |
|
VMware Carbon Black Cloud Workload Appliance 1.x |
https://community.carbonblack.com/t5/Threat-Research-Docs/Log4Shell-Mitigation-Steps-for-VMware-Carbon-Black-Cloud/ta-p/109167 |
|
VMware Carbon Black EDR Server 7.x, 6.x |
https://community.carbonblack.com/t5/Threat-Research-Docs/Log4Shell-Mitigation-Steps-for-VMware-Carbon-Black-EDR/ta-p/109168 |
|
VMware Tanzu GemFire 9.x, 8.x |
https://community.pivotal.io/s/article/Workaround-to-address-CVE-2021-44228-Apache-Log4j-Remote-Code-Execution-for-all-GemFire-versions?language=en_US |
|
VMware Tanzu Greenplum 6.x |
https://community.pivotal.io/s/article/Workaround-to-address-CVE-2021-44228-Apache-Log4j-Remote-Code-Execution-for-All-Greenplum-Versions?language=en_US |
|
VMware Tanzu Operations Manager 2.x |
https://community.pivotal.io/s/article/5004y00001mPn2N1639255611105?language=en_US |
|
VMware Tanzu Application Service for VMs 2.x |
https://community.pivotal.io/s/article/Workaround-instructions-to-address-CVE-2021-44228-in-Tanzu-Application-Service-2-7-through-2-12?language=en_US |
|
VMware Tanzu Kubernetes Grid Integrated Edition 1.x |
https://community.pivotal.io/s/article/Workaround-instructions-to-address-CVE-2021-44228-in-Tanzu-Kubernetes-Grid-Integrated?language=en_US |
|
VMware Cloud Foundation4.x, 3.x |
https://kb.vmware.com/s/article/87095 |
|
VMware Workspace ONE Access Connector (VMware Identity Manager Connector) 21.x, 20.10.x, 19.03.0.1 |
https://kb.vmware.com/s/article/87091 |
|
VMware Horizon DaaS 9.1.x, 9.0.x |
https://kb.vmware.com/s/article/87101 |
|
VMware NSX Data Center for vSphere |
https://kb.vmware.com/s/article/87099 |
|
VMware AppDefense Appliance |
https://community.carbonblack.com/t5/Threat-Research-Docs/Log4Shell-Mitigation-Steps-for-AppDefense/ta-p/109180 |
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







