CVE-2019-0542: Code Injection
A remote code execution vulnerability exists in Xterm.js before versions 3.8.1, 3.9.2 and 3.10.1 when the component mishandles special characters.
Upstream Releases:
https://github.com/xtermjs/xterm.js/releases/tag/3.8.1 https://github.com/xtermjs/xterm.js/releases/tag/3.9.2 https://github.com/xtermjs/xterm.js/releases/tag/3.10.1
Other sources
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0542?
CVE-2019-0542 has been classified with a high severity as it allows for remote code execution.
How do I fix CVE-2019-0542?
To mitigate CVE-2019-0542, upgrade Xterm.js to version 3.8.1, 3.9.2, or 3.10.1 or later.
What systems are affected by CVE-2019-0542?
CVE-2019-0542 affects versions of Xterm.js prior to 3.8.1, 3.9.2, and 3.10.1, as well as various versions of Red Hat OpenShift Container Platform.
What kind of vulnerability is CVE-2019-0542?
CVE-2019-0542 is a remote code execution vulnerability that arises from mishandling special characters.
What are the consequences of CVE-2019-0542?
Exploiting CVE-2019-0542 could allow an attacker to execute arbitrary code on the affected system.