PT-2019-2577 · Xterm.Js · Xterm.Js

Published

2019-01-09

·

Updated

2022-10-27

·

CVE-2019-0542

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xterm.js (affected versions not specified)
Description A remote code execution issue exists due to the mishandling of special characters by the xterm.js component. This can allow a remote attacker to execute arbitrary code. The vulnerability is related to the lack of input data sanitization. It was also discovered that this issue could be exploited in the AWS CloudShell service, potentially leading to remote code execution on EC2 servers accessed through the CloudShell console. The successful exploitation of this vulnerability could provide an attacker with a powerful entry point into the AWS infrastructure, including managed Kubernetes services like EKS and ESC.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2019-02452
CVE-2019-0542
GHSA-MC23-976P-J42X
RHSA-2019:1422
RHSA-2019:2551
RHSA-2019:2552

Affected Products

Xterm.Js