Lucene search

K
ibmIBMCA58581316DE4C9285098B2A4971BAD8939F8990F788DB5BE69B72F009EC26B3
HistoryOct 26, 2021 - 8:39 p.m.

Security Bulletin: Openstack Compute (Nova) noVNC proxy

2021-10-2620:39:48
www.ibm.com
12
openstack nova
vulnerability
fix
ibm powervc 1.4.4.2
2.0.0.0
2.0.1
cve-2021-3654

EPSS

0.926

Percentile

99.0%

Summary

Fix OpenStack Nova allowing a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the noVNC component. By modifying untrusted URL input using multiple backslashes, an attacker could exploit this vulnerability to redirect a victim to arbitrary website

Vulnerability Details

CVEID:CVE-2021-3654
**DESCRIPTION:**OpenStack Nova could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the noVNC component. By modifying untrusted URL input using multiple backslashes (“/”), an attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/206478 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
PowerVC

1.4.4.2

2.0.0.0

2.0.1

Remediation/Fixes

Product(s) Version APAR Remediation
IBM PowerVC 1.4.4.2
IT38556 https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=ibm%7EOther%20software&product=ibm/Other+software/PowerVC&release=1.4.4.2&platform=All&function=fixId&fixids=1.4.4.2-PowerVC-RHEL-NOARCH-APAR-IT38556&includeRequisites=1&includeSupersedes=0&downloadMethod=http&login=true
IBM PowerVC 2.0.0.0 IT38556 https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=ibm%7EOther%20software&product=ibm/Other+software/PowerVC&release=2.0.0.0&platform=All&function=fixId&fixids=2.0.0.0-PowerVC-RHEL-SLES-NOARCH-APAR-IT38556&includeRequisites=1&includeSupersedes=0&downloadMethod=http
IBM PowerVC 2.0.1 IT38556 https://ibm.com/support/fixcentral/swg/downloadFixes?parent=ibm~Other%20software&product=ibm/Other+software/PowerVC&release=2.0.1&platform=All&function=fixId&fixids=2.0.1-PowerVC-RHEL-SLES-NOARCH-APAR-IT38556&includeRequisites=1&includeSupersedes=0&downloadMethod=http

Workarounds and Mitigations

None

EPSS

0.926

Percentile

99.0%