novnc: XSS vulnerability via the messages propagated to the status field
Published Sep 25, 2019
6.1
MEDIUMCVSS 3.1
EPSS 4.79%
Description
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
Affected products
No data.
Configuration 2
- 8.0
- 9.0
Configuration 3
- 16.04
No data.
Red Hat OpenStack Platform 13.0 (Queens)
novnc-0:1.1.0-2.el7ost
Fixed · RHSA-2020:0754
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
novnc-0:1.1.0-2.el7ost
Fixed · RHSA-2020:0754
Red Hat Virtualization Engine 4.4
novnc-0:1.1.0-1.el8ost
Fixed · RHSA-2020:3247
Red Hat OpenStack Platform 10 (Newton)
novnc
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
novnc
Fix deferred
Red Hat OpenStack Platform 15 (Stein)
novnc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13.0 (Queens) | novnc-0:1.1.0-2.el7ost | Fixed | RHSA-2020:0754 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | novnc-0:1.1.0-2.el7ost | Fixed | RHSA-2020:0754 |
| Red Hat Virtualization Engine 4.4 | novnc-0:1.1.0-1.el8ost | Fixed | RHSA-2020:3247 |
| Red Hat OpenStack Platform 10 (Newton) | novnc | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | novnc | Fix deferred | n/a |
| Red Hat OpenStack Platform 15 (Stein) | novnc | Not affected | n/a |
@novnc/novnc
npm
Introduced 0 Fixed 0.6.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @novnc/novnc | 0 | 0.6.2 |
Remediation
Red Hat mitigation
There is no known mitigation for this issue, the flaw can only be resolved by applying updates.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (56 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.79% (0.04788) | 91.65th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.81% (0.04810) | 90.79th | v5 (v2026.06.15) |
| May 29, 2026 | 6.49% (0.06495) | 91.24th | v4 (v2025.03.14) |
| May 26, 2026 | 8.31% (0.08306) | 92.36th | v4 (v2025.03.14) |
| May 24, 2026 | 6.49% (0.06495) | 91.21th | v4 (v2025.03.14) |
| May 22, 2026 | 8.31% (0.08306) | 92.35th | v4 (v2025.03.14) |
| May 13, 2026 | 6.49% (0.06495) | 91.19th | v4 (v2025.03.14) |
| Mar 22, 2026 | 8.31% (0.08306) | 92.18th | v4 (v2025.03.14) |
| Mar 4, 2026 | 7.25% (0.07253) | 91.47th | v4 (v2025.03.14) |
| Mar 1, 2026 | 5.33% (0.05325) | 89.91th | v4 (v2025.03.14) |
| Feb 4, 2026 | 7.25% (0.07253) | 91.41th | v4 (v2025.03.14) |
| Feb 1, 2026 | 5.33% (0.05325) | 89.84th | v4 (v2025.03.14) |
| Jan 24, 2026 | 7.25% (0.07253) | 91.39th | v4 (v2025.03.14) |
| Jan 16, 2026 | 9.77% (0.09771) | 92.72th | v4 (v2025.03.14) |
| Dec 28, 2025 | 8.31% (0.08306) | 91.96th | v4 (v2025.03.14) |
| Dec 27, 2025 | 5.54% (0.05535) | 90.01th | v4 (v2025.03.14) |
| Dec 17, 2025 | 8.31% (0.08306) | 91.95th | v4 (v2025.03.14) |
| Dec 4, 2025 | 7.25% (0.07253) | 91.28th | v4 (v2025.03.14) |
| Dec 1, 2025 | 5.33% (0.05325) | 89.72th | v4 (v2025.03.14) |
| Nov 4, 2025 | 7.25% (0.07253) | 91.22th | v4 (v2025.03.14) |
| Nov 1, 2025 | 5.33% (0.05325) | 89.63th | v4 (v2025.03.14) |
| Oct 28, 2025 | 7.25% (0.07253) | 91.22th | v4 (v2025.03.14) |
| Oct 27, 2025 | 4.81% (0.04809) | 89.03th | v4 (v2025.03.14) |
| Oct 4, 2025 | 7.25% (0.07253) | 91.26th | v4 (v2025.03.14) |
| Sep 4, 2025 | 4.81% (0.04809) | 89.09th | v4 (v2025.03.14) |
| Sep 1, 2025 | 3.50% (0.03498) | 87.22th | v4 (v2025.03.14) |
| Aug 4, 2025 | 4.81% (0.04809) | 89.09th | v4 (v2025.03.14) |
| Aug 1, 2025 | 3.50% (0.03498) | 87.25th | v4 (v2025.03.14) |
| Jul 4, 2025 | 5.15% (0.05154) | 89.42th | v4 (v2025.03.14) |
| Jul 1, 2025 | 4.12% (0.04122) | 88.18th | v4 (v2025.03.14) |
| Jun 4, 2025 | 5.15% (0.05154) | 89.36th | v4 (v2025.03.14) |
| Jun 1, 2025 | 4.12% (0.04122) | 88.11th | v4 (v2025.03.14) |
| May 30, 2025 | 5.15% (0.05154) | 89.35th | v4 (v2025.03.14) |
| Apr 20, 2025 | 2.14% (0.02142) | 83.25th | v4 (v2025.03.14) |
| Apr 18, 2025 | 5.65% (0.05654) | 89.83th | v4 (v2025.03.14) |
| Apr 6, 2025 | 7.67% (0.07675) | 91.11th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.49% (0.06495) | 90.18th | v4 (v2025.03.14) |
| Mar 29, 2025 | 16.97% (0.16971) | 91.68th | v4 (v2025.03.14) |
| Mar 28, 2025 | 6.49% (0.06495) | 90.19th | v4 (v2025.03.14) |
| Mar 27, 2025 | 16.97% (0.16971) | 94.09th | v4 (v2025.03.14) |
| Mar 20, 2025 | 11.04% (0.11040) | 92.89th | v4 (v2025.03.14) |
| Mar 19, 2025 | 16.97% (0.16971) | 94.20th | v4 (v2025.03.14) |
| Mar 17, 2025 | 11.04% (0.11040) | 92.91th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.32% (0.00316) | 71.26th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.35% (0.00352) | 71.11th | v3 (v2023.03.01) |
| Jan 19, 2024 | 0.35% (0.00352) | 69.01th | v3 (v2023.03.01) |
| Sep 1, 2023 | 0.51% (0.00506) | 73.54th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.44% (0.00443) | 70.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 11.61% (0.11613) | 95.06th | v2 (v2022.01.01) |
| Apr 1, 2022 | 11.61% (0.11613) | 94.67th | v2 (v2022.01.01) |
| Feb 4, 2022 | 11.61% (0.11613) | 88.84th | v2 (v2022.01.01) |
| Feb 3, 2022 | 9.98% (0.09982) | 87.28th | v1 |
| Jan 6, 2022 | 9.98% (0.09982) | 87.13th | v1 |
| Dec 29, 2021 | 9.98% (0.09982) | 95.13th | v1 |
| Sep 1, 2021 | 9.15% (0.09152) | 93.82th | v1 |
| Apr 14, 2021 | 9.15% (0.09152) | 0.00th | v1 |
References (17)
- https://access.redhat.com/errata/RHSA-2020:0754 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-18635 Vendor Advisory
- https://bugs.launchpad.net/horizon/+bug/1656435 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1765660 Issue Tracking
- https://github.com/ShielderSec/cve-2017-18635 x_refsource_MISCThird Party Advisory
- https://github.com/advisories/GHSA-49rv-g7w5-m8xx Advisory
- https://github.com/novnc/noVNC/commit/6048299a138e078aed210f163111698c8c526a13#diff-286f7dc7b881e942e97cd50c10898f03L534 x_refsource_MISCPatchThird Party Advisory
- https://github.com/novnc/noVNC/issues/748 x_refsource_MISCPatchThird Party Advisory
- https://github.com/novnc/noVNC/releases/tag/v0.6.2 x_refsource_MISCRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00004.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00024.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-18635
- https://snyk.io/vuln/SNYK-JS-NOVNCNOVNC-469136
- https://usn.ubuntu.com/4522-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-18635
- https://www.npmjs.com/advisories/1204
- https://www.shielder.it/blog/exploiting-an-old-novnc-xss-cve-2017-18635-in-openstack/ x_refsource_MISCExploitThird Party Advisory
Change history (0)
No recorded changes yet.