6.1
CVSSv3

CVE-2021-3654

Published: 02/03/2022 Updated: 03/05/2023
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova

redhat openstack platform 16.1

redhat openstack platform 16.2

Vendor Advisories

Synopsis Moderate: Red Hat OpenStack Platform 161 (openstack-nova) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for openstack-nova is now available for Red Hat OpenStackPlatform 161 (Train)R ...
Synopsis Moderate: Red Hat OpenStack Platform 162 (openstack-nova) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for openstack-nova is now available for Red Hat OpenStackPlatform 162 (Train)R ...
Debian Bug report logs - #991441 nova: CVE-2021-3654: novnc allows open redirection Package: src:nova; Maintainer for src:nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Jul 2021 18:30:02 UTC Severity: important Tags: security, upstream ...

Mailing Lists

=========================================== OSSA-2021-002: Open Redirect in noVNC proxy =========================================== :Date: July 29, 2021 :CVE: CVE-2021-3654 Affects ~~~~~~~ - Nova: <2123, >=2200 <2223, >=2300 <2302 Description ~~~~~~~~~~~ Swe Aung, Shahaan Ayyub, and Salman Khan with the Monash Universi ...
=========================================== OSSA-2021-002: Open Redirect in noVNC proxy =========================================== :Date: July 29, 2021 :CVE: CVE-2021-3654 Affects ~~~~~~~ - Nova: <2123, >=2200 <2223, >=2300 <2303 Description ~~~~~~~~~~~ Swe Aung, Shahaan Ayyub, and Salman Khan with the Monash Universi ...