CVE-2017-18635 describes a Cross-Site Scripting (XSS) vulnerability in noVNC versions prior to 0.6.2, allowing a malicious VNC server to inject arbitrary HTML into the noVNC web page via the status field. This medium-severity vulnerability (CVSS 6.1) has a low attack complexity and requires user interaction, potentially leading to limited impact on confidentiality and integrity. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, there is evidence of community discussion and media coverage, including an article detailing its exploitation in OpenStack.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.6.2CPE matchmatch criteria | cpe:2.3:a:novnc:novnc:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* | ||
13CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.