Security Advisory: VMware Cloud Director
Another high rating of CVSSv3 of 9.8 was released here on VMware Cloud Director appliance.
For those not aware, the virtual appliance is a prepackaged virtual machine with added configuration bedded in for easy deployment.
This time it is due to authentication bypass vulnerability which allows a user to bypass authenticating on port 22 (ssh) or port 5480 after upgraded to version 10.5 from a previously older version.
To resolve this, the updated kb has been released and it provide a script for the workaround to fix this.
For those not aware, the virtual appliance is a prepackaged virtual machine with added configuration bedded in for easy deployment.
This time it is due to authentication bypass vulnerability which allows a user to bypass authenticating on port 22 (ssh) or port 5480 after upgraded to version 10.5 from a previously older version.
To resolve this, the updated kb has been released and it provide a script for the workaround to fix this.
Do note that this affect only VMware Cloud Director version 10.5 which was upgraded from older version. Not on new deployment or other versions.
Comments