Back

MEDIUM

novnc: XSS vulnerability via the messages propagated to the status field

Published Sep 25, 2019

Description

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

Affected products

Remediation

Red Hat mitigation

There is no known mitigation for this issue, the flaw can only be resolved by applying updates.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 25, 2019
Updated Aug 5, 2024
Reserved Sep 25, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 12, 2019
GHSA-49RV-G7W5-M8XX