Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49rv-g7w5-m8xx

Опубликовано: 28 авг. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-Site Scripting in @novnc/novnc

Versions of @novnc/novnc prior to 0.6.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to validate input from the remote VNC server such as the VNC server name. This allows an attacker in control of the remote server to execute arbitrary JavaScript in the noVNC web page. It affects any users of include/ui.js and users of vnc_auto.html and vnc.html.

Recommendation

Upgrade to version 0.6.2 or later.

Пакеты

Наименование

@novnc/novnc

npm
Затронутые версииВерсия исправления

< 0.6.2

0.6.2

EPSS

Процентиль: 90%
0.05325
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
redhat
около 7 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
nvd
больше 6 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
debian
больше 6 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the ...

EPSS

Процентиль: 90%
0.05325
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79