{"id":"CVE-2021-3654","details":"A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.","aliases":["GHSA-vqp6-j452-j6wp","PYSEC-2026-693"],"modified":"2026-07-08T05:57:12.909795271Z","published":"2022-03-02T23:15:08.730Z","database_specific":{"unresolved_ranges":[{"vendor_product":"openstack:nova","cpes":["cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"22.0.0"},{"fixed":"22.2.3"},{"introduced":"23.0.0"},{"fixed":"23.0.3"}],"source":"CPE_RANGE"},{"source":"CPE_STRING","vendor_product":"redhat:openstack_platform","cpes":["cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"16.1"},{"last_affected":"16.1"},{"introduced":"16.2"},{"last_affected":"16.2"}]}]},"references":[{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202305-02"},{"type":"FIX","url":"https://bugs.launchpad.net/nova/+bug/1927677"},{"type":"FIX","url":"https://bugs.python.org/issue32084"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1961439"},{"type":"FIX","url":"https://opendev.org/openstack/nova/commit/04d48527b62a35d912f93bc75613a6cca606df66"},{"type":"FIX","url":"https://opendev.org/openstack/nova/commit/8906552cfc2525a44251d4cf313ece61e57251eb"},{"type":"FIX","url":"https://security.openstack.org/ossa/OSSA-2021-002.html"},{"type":"FIX","url":"https://www.openwall.com/lists/oss-security/2021/07/29/2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openstack/nova","events":[{"introduced":"0"},{"fixed":"6f774f226bcf8c5468de92d3eea80962656754cd"}],"database_specific":{"cpe":"cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"21.2.3"}],"source":"CPE_RANGE"}}],"versions":["21.2.2","21.2.1","21.2.0","21.1.2","21.1.1","21.1.0","21.0.0.0rc2","21.0.0","21.0.0.0rc1","20.0.0.0rc1","19.0.0.0rc1","18.0.0.0rc1","18.0.0.0b3","18.0.0.0b2","18.0.0.0b1","17.0.0.0b3","17.0.0.0rc1","17.0.0.0b2","17.0.0.0b1","16.0.0.0rc1","16.0.0.0b3","16.0.0.0b2","16.0.0.0b1","15.0.0.0rc1","15.0.0.0b3","15.0.0.0b2","15.0.0.0b1","14.0.0.0rc1","14.0.0.0b3","14.0.0.0b2","14.0.0.0b1","13.0.0.0rc1","13.0.0.0b3","13.0.0.0b2","13.0.0.0b1","12.0.0.0rc1","12.0.0.0b3","12.0.0.0b2","12.0.0.0b1","12.0.0a0","2015.1.0rc1","2015.1.0b3","2015.1.0b2","2015.1.0b1","2014.2.rc1","2014.2.b3","2014.2.b2","2014.2.b1","2014.1.rc1","2014.1.b3","2014.1.b2","2014.1.b1","2013.2.rc1","2013.2.b3","2013.1.rc1","folsom-2","folsom-1","essex-1","diablo-1","2011.2","2011.2rc1","2011.2gamma1","2011.1rc1","2011.1","2010.1","0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3654.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}