PT-2019-8548 · Novnc+2 · Novnc+2

David Wyde

·

Publicado

2017-11-16

·

Atualizado

2022-04-06

·

CVE-2017-18635

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions noVNC versions prior to 0.6.2
Description A Cross-Site Scripting (XSS) issue was discovered in noVNC, where a remote VNC server could inject arbitrary HTML into the noVNC web page via messages propagated to the status field, such as the VNC server name. This allows an attacker in control of the remote server to execute arbitrary JavaScript in the noVNC web page. The issue affects users of include/ui.js and users of vnc auto.html and vnc.html.
Recommendations Upgrade to version 0.6.2 or later. As a temporary workaround, consider restricting input from the remote VNC server to minimize the risk of exploitation. Avoid using the VNC server name variable in the affected noVNC web page until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2653
CVE-2017-18635
DLA-1946-1
DLA-2854-1
GHSA-49RV-G7W5-M8XX
MGASA-2020-0374
RHSA-2020:0754
RHSA-2020:3247
USN-4522-1

Produtos afetados

Alt Linux
Ubuntu
Novnc