CVE-2017-18635: XSS
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
Other sources
An XSS vulnerability was discovered in noVNC in which arbitrary HTML could be injected into the noVNC web page. An attacker having access to a VNC server could use target host values in a crafted URL to gain access to secure information (such as VM tokens).
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2017-18635?
The severity of CVE-2017-18635 is medium with a CVSS score of 6.1.
How can an attacker exploit CVE-2017-18635?
An attacker can exploit CVE-2017-18635 by injecting arbitrary HTML into the noVNC web page.
What versions of noVNC are affected by CVE-2017-18635?
Versions before 0.6.2 of noVNC are affected by CVE-2017-18635.
How can the vulnerability in noVNC be fixed?
To fix the vulnerability in noVNC, update to version 0.6.2 or above.
Are there any references for CVE-2017-18635?
Yes, you can find references for CVE-2017-18635 at the following links: [Link 1](https://github.com/novnc/noVNC/issues/748), [Link 2](https://github.com/novnc/noVNC/commit/6048299a138e078aed210f163111698c8c526a13#diff-286f7dc7b881e942e97cd50c10898f03L534), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1765662).