VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22054.json"
[
{
"events": [
{
"introduced": "20.0.8.0"
},
{
"fixed": "20.0.8.36"
}
]
},
{
"events": [
{
"introduced": "20.11.0.0"
},
{
"fixed": "20.11.0.40"
}
]
},
{
"events": [
{
"introduced": "21.2.0.0"
},
{
"fixed": "21.2.0.27"
}
]
},
{
"events": [
{
"introduced": "21.5.0.0"
},
{
"fixed": "21.5.0.37"
}
]
}
]