{
  "threat_severity" : "Moderate",
  "public_date" : "2020-08-04T09:00:00Z",
  "bugzilla" : {
    "description" : "ovirt-engine: Redirect to arbitrary URL allows for phishing",
    "id" : "1847420",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1847420"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-451->CWE-601",
  "details" : [ "An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.", "An Open redirect vulnerability was found in ovirt-engine versions 4.4.1 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality." ],
  "statement" : "In Red Hat Gluster Storage 3, ovirt-engine(included in rhsc) was shipped as a part of Red Hat Gluster Storage Console that is no longer supported for use with Red Hat Gluster Storage 3.5. Red Hat Gluster Storage Web Administration is now the recommended monitoring tool for Red Hat Storage Gluster clusters. However, the vulnerable code is not included in the shipped version of ovirt-engine hence not affected by this flaw.",
  "acknowledgement" : "Red Hat would like to thank Chen Huiliang (QIANXIN CodeSafe Team) and Chen RuiQi (QIANXIN CodeSafe Team) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Virtualization Engine 4.4",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3247",
    "cpe" : "cpe:/a:redhat:rhev_manager:4.4:el8",
    "package" : "org.ovirt.engine-root-0:4.4.1.8-7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Storage 3",
    "fix_state" : "Out of support scope",
    "package_name" : "rhsc",
    "cpe" : "cpe:/a:redhat:storage:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-10775\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-10775" ],
  "name" : "CVE-2020-10775",
  "csaw" : false
}