Open Redirect Vulnerability in oVirt Engine by Red Hat
CVE-2020-10775
5.3MEDIUM
Summary
An Open Redirect vulnerability exists in oVirt Engine versions 4.4 and earlier, allowing remote attackers to deceive users into visiting malicious websites. This could facilitate phishing attacks, as unsuspecting users will be redirected without clear visibility of the destination URL. When exploited, this vulnerability poses a significant risk to user confidentiality, as attackers can trick users into disclosing sensitive information.
Affected Version(s)
ovirt-engine ovirt-engine versions before 4.4.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved