VMware Horizon Community
Markus_Gundelac
Contributor
Contributor

Mitigation instructions to address CVE-2021-44228 in VMware Horizon (87073)

For Horizon Agents is a note: "7.13.x: Upgrade to newer versions on supported product versions for mitigation."

What that means? We use Horizon 7.13 Connection Server with the latest Agent version? Have we now to wait for a new Agent version?

0 Kudos
3 Replies
SurajRoy
Enthusiast
Enthusiast

Currently View 7.x and 8.x both are impacted.

It is impacting any component which is using Apache Log4j2 all versions from 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0.
You need to apply the Workaround as patch is pending.

 

 

0 Kudos
ofox
VMware Employee
VMware Employee

0 Kudos
Stevenson42
Contributor
Contributor

Am I reading this correctly, the manual work around is to remove HTML access?

0 Kudos