Lucene search

K
cvelistRedhatCVELIST:CVE-2021-3654
HistoryMar 02, 2022 - 12:00 a.m.

CVE-2021-3654

2022-03-0200:00:00
CWE-601
redhat
www.cve.org
6
openstack
nova
console proxy
novnc
redirect
url
vulnerability

AI Score

6.5

Confidence

High

EPSS

0.926

Percentile

99.0%

A vulnerability was found in openstack-nova’s console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "openstack-nova",
    "versions": [
      {
        "version": "Affects - Nova: <21.2.3, >=22.0.0 <22.2.3, >=23.0.0 <23.0.3 | Fixed-In 21.2.3, 22.3.0, and 23.1.0",
        "status": "affected"
      }
    ]
  }
]

AI Score

6.5

Confidence

High

EPSS

0.926

Percentile

99.0%