Description
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1946-1 | novnc security update |
Debian DLA |
DLA-2854-1 | novnc security update |
EUVD |
EUVD-2020-0588 | An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. |
Github GHSA |
GHSA-49rv-g7w5-m8xx | Cross-Site Scripting in @novnc/novnc |
Ubuntu USN |
USN-4522-1 | noVNC vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:28:55.736Z
Reserved: 2019-09-25T00:00:00.000Z
Link: CVE-2017-18635
No data.
Status : Modified
Published: 2019-09-25T23:15:09.937
Modified: 2024-11-21T03:20:32.157
Link: CVE-2017-18635
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN