CVE-2021-3654Medium· 6.1▾ TwilightPoC availableOpen Redirect in CPython that affects users of OpenStack Nova
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 5.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
27%
Nuclei ×1
A vulnerability was found in CPython which is used by openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
nova < 21.2.3nova >= 22.0.0, < 22.2.3nova >= 23.0.0, < 23.0.3Upgrade to a patched release:
nova 21.2.3nova 22.2.3nova 23.0.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2014-3517MediumOpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2015-0259MediumOpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
CVE-2014-0167MediumOpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
CVE-2015-3280MediumOpenStack Compute (nova) allows remote authenticated users to cause a denial of service
CVE-2013-4179MediumOpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
CVE-2014-3608MediumOpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service