QID 980721
QID 980721: Nodejs (npm) Security Update for @novnc/novnc (GHSA-49rv-g7w5-m8xx)
Versions of `@novnc/novnc` prior to 0.6.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to validate input from the remote VNC server such as the VNC server name. This allows an attacker in control of the remote server to execute arbitrary JavaScript in the noVNC web page. It affects any users of `include/ui.js` and users of `vnc_auto.html` and `vnc.html`.
## Recommendation
Upgrade to version 0.6.2 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-49rv-g7w5-m8xx for updates pertaining to this vulnerability.
Vendor References
- GHSA-49rv-g7w5-m8xx -
github.com/advisories/GHSA-49rv-g7w5-m8xx
CVEs related to QID 980721
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-49rv-g7w5-m8xx | @novnc/novnc |
|