CVE-2020-10775

Severity
5.3MEDIUM
EPSS
0.4%
top 38.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateMay 24

Description

An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages3 packages

CVEListV5ovirt-engineovirt-engine versions before 4.4.2

🔴Vulnerability Details

2
GHSA
GHSA-7wqr-p83r-v6rj: An Open redirect vulnerability was found in ovirt-engine versions 42022-05-24
CVEList
CVE-2020-10775: An Open redirect vulnerability was found in ovirt-engine versions 42020-08-24

📋Vendor Advisories

1
Red Hat
ovirt-engine: Redirect to arbitrary URL allows for phishing2020-08-04

💬Community

1
Bugzilla
CVE-2020-10775 ovirt-engine: Redirect to arbitrary URL allows for phishing2020-06-16
CVE-2020-10775 (MEDIUM CVSS 5.3) | An Open redirect vulnerability was | cvebase.io