Comment 21 for bug 1927677

Revision history for this message
Joshua Padman (jpadman) wrote : Re: novnc allowing open direction which could potentially be used for phishing

The last OSSA that was released was also for an open redirect.
https://security.openstack.org/ossa/OSSA-2020-008.html

Its not a fancy vulnerability but it is one that can lead to far more significant issues. Ideally a CVE would be assigned to this, though maybe in the interest of consistency an OSSA may be required too?