← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1927677] Re: [OSSA-2021-002] Open Redirect in noVNC proxy (CVE-2021-3654)

 

It is confirmed that the original fix was incomplete. A new fix is being
merged to master https://review.opendev.org/c/openstack/nova/+/805654
(and then backported)

** Changed in: nova
       Status: Fix Released => In Progress

** Changed in: nova/wallaby
       Status: Fix Released => Confirmed

** Changed in: nova/ussuri
       Status: Fix Committed => Confirmed

** Changed in: nova/train
       Status: In Progress => Confirmed

** Changed in: nova/stein
       Status: In Progress => Confirmed

** Changed in: nova/victoria
       Status: Fix Committed => Confirmed

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/1927677

Title:
  [OSSA-2021-002] Open Redirect in noVNC proxy (CVE-2021-3654)

Status in OpenStack Compute (nova):
  In Progress
Status in OpenStack Compute (nova) stein series:
  Confirmed
Status in OpenStack Compute (nova) train series:
  Confirmed
Status in OpenStack Compute (nova) ussuri series:
  Confirmed
Status in OpenStack Compute (nova) victoria series:
  Confirmed
Status in OpenStack Compute (nova) wallaby series:
  Confirmed
Status in OpenStack Security Advisory:
  Fix Released

Bug description:
  This bug report is related to Security.

  Currently novnc is allowing open direction, which could potentially be
  used for phishing attempts

  To test.
  https://<sites' vnc domain>//example.com/%2F..
  include .. at the end

  For example:
  http://vncproxy.my.domain.com//example.com/%2F..

  It will redirect to example.com. You can replace example.com with some
  legitimate domain or spoofed domain.

  The description of the risk  is
  By modifying untrusted URL input to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
  Because the server name in the modified link is identical to the original site, phishing attempts may have a more trustworthy appearance.

To manage notifications about this bug go to:
https://bugs.launchpad.net/nova/+bug/1927677/+subscriptions