Reflected cross-site scripting (XSS) In novnc
Description
Cross-Site Scripting in @novnc/novnc
Versions of @novnc/novnc prior to 0.6.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to validate input from the remote VNC server such as the VNC server name. This allows an attacker in control of the remote server to execute arbitrary JavaScript in the noVNC web page. It affects any users of include/ui.js and users of vnc_auto.html and vnc.html.
Recommendation
Upgrade to version 0.6.2 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 1:1.0.0-1 | ||
npm | 0.6.2 | ||
debian 14 | 1:1.0.0-1 | ||
debian 12 | 1:1.0.0-1 | ||
debian 13 | 1:1.0.0-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.