Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-18635

Опубликовано: 25 сент. 2019
Источник: debian
EPSS Низкий

Описание

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
novncfixed1:1.0.0-1package

Примечания

  • https://bugs.launchpad.net/horizon/+bug/1656435

  • https://github.com/novnc/noVNC/commit/6048299a138e078aed210f163111698c8c526a13#diff-286f7dc7b881e942e97cd50c10898f03L534

  • https://github.com/novnc/noVNC/issues/748

EPSS

Процентиль: 91%
0.07253
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
redhat
около 7 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
nvd
больше 6 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
github
больше 5 лет назад

Cross-Site Scripting in @novnc/novnc

EPSS

Процентиль: 91%
0.07253
Низкий