VDB
KO
MEDIUM 6.1

GHSA-vqp6-j452-j6wp

Open Redirect in CPython that affects users of OpenStack Nova

Details

A vulnerability was found in CPython which is used by openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / nova
Introduced in: 0 Fixed in: 21.2.3
Fix pip install --upgrade 'nova>=21.2.3'
PyPI / nova
Introduced in: 22.0.0 Fixed in: 22.2.3
Fix pip install --upgrade 'nova>=22.2.3'
PyPI / nova
Introduced in: 23.0.0 Fixed in: 23.0.3
Fix pip install --upgrade 'nova>=23.0.3'

References