PT-2019-8548 · Novnc+2 · Novnc+2
David Wyde
·
Published
2017-11-16
·
Updated
2022-04-06
·
CVE-2017-18635
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
noVNC versions prior to 0.6.2
Description
A Cross-Site Scripting (XSS) issue was discovered in noVNC, where a remote VNC server could inject arbitrary HTML into the noVNC web page via messages propagated to the status field, such as the VNC server name. This allows an attacker in control of the remote server to execute arbitrary JavaScript in the noVNC web page. The issue affects users of
include/ui.js and users of vnc auto.html and vnc.html.Recommendations
Upgrade to version 0.6.2 or later. As a temporary workaround, consider restricting input from the remote VNC server to minimize the risk of exploitation. Avoid using the
VNC server name variable in the affected noVNC web page until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ubuntu
Novnc