URL Redirection Vulnerability in OpenStack Nova's noVNC Console Proxy
CVE-2021-3654
What is CVE-2021-3654?
A vulnerability exists in OpenStack Nova's console proxy, noVNC, where a maliciously crafted URL can redirect the user to an unwanted location. This situation poses potential security risks by forcing users to visit unauthorized sites, which could lead to exposure of sensitive information or further exploitation. Proper input validation and sanitization measures are necessary to mitigate this risk and protect users from such attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openstack-nova Affects - Nova: <21.2.3, >=22.0.0 <22.2.3, >=23.0.0 <23.0.3 | Fixed-In 21.2.3, 22.3.0, and 23.1.0
References
EPSS Score
85% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
