CVE-2020-10775: Medium severity Oracle Virtualization vulnerability
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.
Other sources
An Open redirect vulnerability was found in ovirt-engine versions 4.4.1 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.
Open redirect vulnerability in ovirt-engine 4.4 and earlier allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser the critical part of the URL is no longer visible.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10775?
CVE-2020-10775 is an open redirect vulnerability found in ovirt-engine versions 4.4 and earlier that allows remote attackers to redirect users to arbitrary websites and attempt phishing attacks.
What is the severity of CVE-2020-10775?
The severity of CVE-2020-10775 is medium with a CVSS score of 5.3.
How can the open redirect vulnerability in ovirt-engine be fixed?
To fix the open redirect vulnerability in ovirt-engine, users should update to version 4.4.2 or later.
What is the affected software for CVE-2020-10775?
The affected software for CVE-2020-10775 includes ovirt-engine versions 4.4.1 and earlier.
Where can I find more information about CVE-2020-10775?
More information about CVE-2020-10775 can be found at the following references: [CVE-2020-10775](https://www.cve.org/CVERecord?id=CVE-2020-10775), [NIST CVE-2020-10775](https://nvd.nist.gov/vuln/detail/CVE-2020-10775), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1847420), and [Red Hat Advisory RHSA-2020:3247](https://access.redhat.com/errata/RHSA-2020:3247).