| Vulnerability Name: | CVE-2020-10775 (CCN-187207) | ||||||||||||
| Assigned: | 2020-06-16 | ||||||||||||
| Published: | 2020-06-16 | ||||||||||||
| Updated: | 2020-09-04 | ||||||||||||
| Summary: | An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality. | ||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-601 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2020-10775 Source: CCN Type: Red Hat Bugzilla Bug 1847420 (CVE-2020-10775) - CVE-2020-10775 ovirt-engine: Redirect to arbitrary URL allows for phishing Source: MISC Type: Issue Tracking, Vendor Advisory, Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1847420 Source: XF Type: UNKNOWN ovirtengine-cve202010775-open-redirect(187207) Source: CCN Type: Ovirt Web site Ovirt | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||