{"api_version":"1","generated_at":"2026-07-23T07:08:47+00:00","cve":"CVE-2017-18635","urls":{"html":"https://cve.report/CVE-2017-18635","api":"https://cve.report/api/cve/CVE-2017-18635.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-18635","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-18635"},"summary":{"title":"CVE-2017-18635","description":"An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-09-25 23:15:00","updated_at":"2022-04-06 17:54:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00024.html","name":"[debian-lts-announce] 20211228 [SECURITY] [DLA 2854-1] novnc security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2854-1] novnc security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/ShielderSec/cve-2017-18635","name":"https://github.com/ShielderSec/cve-2017-18635","refsource":"MISC","tags":[],"title":"GitHub - ShielderSec/cve-2017-18635: PoC for CVE-2017-18635","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.launchpad.net/horizon/+bug/1656435","name":"https://bugs.launchpad.net/horizon/+bug/1656435","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"Bug #1656435 “XSS in noVNC” : Bugs : OpenStack Dashboard (Horizon)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/10/msg00004.html","name":"[debian-lts-announce] 20191005 [SECURITY] [DLA 1946-1] novnc security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1946-1] novnc security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/novnc/noVNC/issues/748","name":"https://github.com/novnc/noVNC/issues/748","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"[Fixed] XSS Vulnerability in noVNC · Issue #748 · novnc/noVNC · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2020:0754","name":"RHSA-2020:0754","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/novnc/noVNC/commit/6048299a138e078aed210f163111698c8c526a13#diff-286f7dc7b881e942e97cd50c10898f03L534","name":"https://github.com/novnc/noVNC/commit/6048299a138e078aed210f163111698c8c526a13#diff-286f7dc7b881e942e97cd50c10898f03L534","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Use textContent instead of innerHTML · novnc/noVNC@6048299 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/4522-1/","name":"USN-4522-1","refsource":"UBUNTU","tags":[],"title":"USN-4522-1: noVNC vulnerability | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.shielder.it/blog/exploiting-an-old-novnc-xss-cve-2017-18635-in-openstack/","name":"https://www.shielder.it/blog/exploiting-an-old-novnc-xss-cve-2017-18635-in-openstack/","refsource":"MISC","tags":[],"title":"Exploiting an old noVNC XSS (CVE-2017-18635) in OpenStack - Shielder","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/novnc/noVNC/releases/tag/v0.6.2","name":"https://github.com/novnc/noVNC/releases/tag/v0.6.2","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"Release v0.6.2 · novnc/noVNC · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-18635","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-18635","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"18635","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"16.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"esm","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18635","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18635","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18635","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novnc","cpe5":"novnc","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18635","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novnc","cpe5":"novnc","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18635","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openstack","cpe6":"13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-18635","qid":"178968","title":"Debian Security Update for novnc (DLA 2854-1)"},{"cve":"CVE-2017-18635","qid":"198198","title":"Ubuntu Security Notification for noVNC vulnerability (USN-4522-1)"},{"cve":"CVE-2017-18635","qid":"980721","title":"Nodejs (npm) Security Update for @novnc/novnc (GHSA-49rv-g7w5-m8xx)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-18635","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/novnc/noVNC/issues/748","refsource":"MISC","name":"https://github.com/novnc/noVNC/issues/748"},{"url":"https://github.com/novnc/noVNC/releases/tag/v0.6.2","refsource":"MISC","name":"https://github.com/novnc/noVNC/releases/tag/v0.6.2"},{"url":"https://bugs.launchpad.net/horizon/+bug/1656435","refsource":"MISC","name":"https://bugs.launchpad.net/horizon/+bug/1656435"},{"url":"https://github.com/novnc/noVNC/commit/6048299a138e078aed210f163111698c8c526a13#diff-286f7dc7b881e942e97cd50c10898f03L534","refsource":"MISC","name":"https://github.com/novnc/noVNC/commit/6048299a138e078aed210f163111698c8c526a13#diff-286f7dc7b881e942e97cd50c10898f03L534"},{"refsource":"MLIST","name":"[debian-lts-announce] 20191005 [SECURITY] [DLA 1946-1] novnc security update","url":"https://lists.debian.org/debian-lts-announce/2019/10/msg00004.html"},{"refsource":"MISC","name":"https://www.shielder.it/blog/exploiting-an-old-novnc-xss-cve-2017-18635-in-openstack/","url":"https://www.shielder.it/blog/exploiting-an-old-novnc-xss-cve-2017-18635-in-openstack/"},{"refsource":"MISC","name":"https://github.com/ShielderSec/cve-2017-18635","url":"https://github.com/ShielderSec/cve-2017-18635"},{"refsource":"REDHAT","name":"RHSA-2020:0754","url":"https://access.redhat.com/errata/RHSA-2020:0754"},{"refsource":"UBUNTU","name":"USN-4522-1","url":"https://usn.ubuntu.com/4522-1/"},{"refsource":"MLIST","name":"[debian-lts-announce] 20211228 [SECURITY] [DLA 2854-1] novnc security update","url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00024.html"}]}},"nvd":{"publishedDate":"2019-09-25 23:15:00","lastModifiedDate":"2022-04-06 17:54:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:novnc:novnc:*:*:*:*:*:*:*:*","versionEndExcluding":"0.6.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"18635","Ordinal":"156656","Title":"CVE-2017-18635","CVE":"CVE-2017-18635","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"18635","Ordinal":"1","NoteData":"An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"18635","Ordinal":"2","NoteData":"2019-09-25","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"18635","Ordinal":"3","NoteData":"2021-12-28","Type":"Other","Title":"Modified"}]}}}