Record summary

CVE-2021-3654 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

openstack-nova

CVE ListAffects - Nova: <21.2.3, >=22.0.0 <22.2.3, >=23.0.0 <23.0.3 | Fixed-In 21.2.3, 22.3.0, and 23.1.0affected
GitHub AdvisoryBefore 21.2.3 · Fixed in 21.2.3affected
22.0.0 to < 22.2.3 · Fixed in 22.2.3affected
23.0.0 to < 23.0.3 · Fixed in 23.0.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMNova noVNC - Open RedirectCVSS 6.1

Nova noVNC contains an open redirect vulnerability. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the open redirect vulnerability in the Nova noVNC application.

WeaknessesCWE-601
Authorsgeeknik
Template tagscve2021cveredirectnovncseclistsopenstackvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

10