A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
2022-03-02T23:15:08.730
2024-11-21T06:22:04.870
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:P/A:N
4.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | nova | < 21.2.3 | Yes |
Application | openstack | nova | < 22.2.3 | Yes |
Application | openstack | nova | < 23.0.3 | Yes |
Application | redhat | openstack_platform | 16.1 | Yes |
Application | redhat | openstack_platform | 16.2 | Yes |