Bugzilla – Bug 1188573
VUL-0: CVE-2021-3654: openstack-nova: novnc allows open redirection
Last modified: 2024-07-08 10:41:24 UTC
rh#1961439 novnc allows open redirection, which could allow phishing attempts. Risk: By modifying untrusted URL input to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. Because the server name in the modified link is identical to the original site, phishing attempts could have a more trustworthy appearance. https://bugs.launchpad.net/nova/+bug/1927677 References: https://bugzilla.redhat.com/show_bug.cgi?id=1961439 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3654
Closing as WONT FIX due to analysis of effort and impact on an LTSS product.