SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-18635

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

MEDIUM 6.1EPSS 4.81%

Does this matter?

Lower severity and a low EPSS score (4.81%). Track it; it rarely justifies an emergency change on its own.

Description

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
4.81% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
novnc/novnc · debian/debian linux · canonical/ubuntu linux · redhat/openstack
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.