CVE-2017-18635
Summary
| CVE | CVE-2017-18635 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-25 23:15:00 UTC |
| Updated | 2022-04-06 17:54:00 UTC |
| Description | An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2854-1] novnc security update |
MLIST |
lists.debian.org |
|
| GitHub - ShielderSec/cve-2017-18635: PoC for CVE-2017-18635 |
MISC |
github.com |
|
| Bug #1656435 “XSS in noVNC” : Bugs : OpenStack Dashboard (Horizon) |
MISC |
bugs.launchpad.net |
Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1946-1] novnc security update |
MLIST |
lists.debian.org |
|
| [Fixed] XSS Vulnerability in noVNC · Issue #748 · novnc/noVNC · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Use textContent instead of innerHTML · novnc/noVNC@6048299 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| USN-4522-1: noVNC vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Exploiting an old noVNC XSS (CVE-2017-18635) in OpenStack - Shielder |
MISC |
www.shielder.it |
|
| Release v0.6.2 · novnc/noVNC · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178968 Debian Security Update for novnc (DLA 2854-1)
- 198198 Ubuntu Security Notification for noVNC vulnerability (USN-4522-1)
- 980721 Nodejs (npm) Security Update for @novnc/novnc (GHSA-49rv-g7w5-m8xx)