Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18635

Опубликовано: 12 янв. 2019
Источник: redhat
CVSS3: 6.1

Описание

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

An XSS vulnerability was discovered in noVNC in which arbitrary HTML could be injected into the noVNC web page. An attacker having access to a VNC server could use target host values in a crafted URL to gain access to secure information (such as VM tokens).

Меры по смягчению последствий

There is no known mitigation for this issue, the flaw can only be resolved by applying updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 10 (Newton)novncWill not fix
Red Hat OpenStack Platform 14 (Rocky)novncFix deferred
Red Hat OpenStack Platform 15 (Stein)novncNot affected
Red Hat OpenStack Platform 13.0 (Queens)novncFixedRHSA-2020:075410.03.2020
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSnovncFixedRHSA-2020:075410.03.2020
Red Hat Virtualization Engine 4.4novncFixedRHSA-2020:324704.08.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1765660novnc: XSS vulnerability via the messages propagated to the status field

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
nvd
больше 6 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
debian
больше 6 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the ...

CVSS3: 6.1
github
больше 5 лет назад

Cross-Site Scripting in @novnc/novnc

6.1 Medium

CVSS3