Vulnerabilities/

Cross-Site Scripting in @novnc/novnc

Severity:
Medium

Description

Versions of @novnc/novnc prior to 0.6.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to validate input from the remote VNC server such as the VNC server name. This allows an attacker in control of the remote server to execute arbitrary JavaScript in the noVNC web page. It affects any users of include/ui.js and users of vnc_auto.html and vnc.html.

Recommendation

Update the @novnc/novnc package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@novnc/novnc
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing