Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10775

Опубликовано: 24 авг. 2020
Источник: nvd
CVSS3: 5.3
CVSS2: 2.6
EPSS Низкий

Описание

An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oracle:virtualization:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:*:*:*:*:*:*:*:*
Версия до 4.4 (включая)

EPSS

Процентиль: 61%
0.0041
Низкий

5.3 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-451
CWE-601

Связанные уязвимости

CVSS3: 5.3
redhat
больше 5 лет назад

An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.

github
больше 3 лет назад

An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.

CVSS3: 5.3
fstec
больше 5 лет назад

Уязвимость средства управления виртуальной инфраструктурой Ovirt, связанная с использованием открытой переадресации, позволяющая нарушителю перенаправить пользователя на произвольные веб-сайт

EPSS

Процентиль: 61%
0.0041
Низкий

5.3 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-451
CWE-601