← back
CVE-2021-3654CWE-601

CVE-2021-3654

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 27%
exploitation probability
27%top 2% of all CVEs
observed exploitation
nono source reports it
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
Affected products
n/a · openstack-nova