Loading HuntDB...

GHSA-hgcm-2jjw-4pr2

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.

Related CVEs

Key Information

GHSA ID
GHSA-hgcm-2jjw-4pr2
Published
May 14, 2022 2:04 AM
Last Modified
May 14, 2022 2:04 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 20, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.