CVE-2021-3654
Open Redirect in CPython that affects users of OpenStack Nova
Record summary
CVE-2021-3654 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
openstack-nova | CVE List | Affects - Nova: <21.2.3, >=22.0.0 <22.2.3, >=23.0.0 <23.0.3 | Fixed-In 21.2.3, 22.3.0, and 23.1.0 | affected |
| GitHub Advisory | Before 21.2.3 · Fixed in 21.2.3 | affected | |
| 22.0.0 to < 22.2.3 · Fixed in 22.2.3 | affected | ||
| 23.0.0 to < 23.0.3 · Fixed in 23.0.3 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMNova noVNC - Open RedirectCVSS 6.1
Nova noVNC contains an open redirect vulnerability. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the open redirect vulnerability in the Nova noVNC application.
Source: ProjectDiscovery