Medium severity6.1NVD Advisory· Published Sep 25, 2019· Updated Jun 17, 2026
CVE-2017-18635
CVE-2017-18635
Description
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@novnc/novncnpm | < 0.6.2 | 0.6.2 |
Affected products
7- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- noVNC/noVNCdescription
Patches
Vulnerability mechanics
References
15- github.com/novnc/noVNC/commit/6048299a138e078aed210f163111698c8c526a13nvdPatchThird Party AdvisoryWEB
- github.com/novnc/noVNC/issues/748nvdPatchThird Party AdvisoryWEB
- www.shielder.it/blog/exploiting-an-old-novnc-xss-cve-2017-18635-in-openstack/nvdExploitThird Party Advisory
- access.redhat.com/errata/RHSA-2020:0754nvdThird Party AdvisoryWEB
- bugs.launchpad.net/horizon/+bug/1656435nvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-49rv-g7w5-m8xxghsaADVISORY
- github.com/novnc/noVNC/releases/tag/v0.6.2nvdRelease NotesThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2019/10/msg00004.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2021/12/msg00024.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2017-18635ghsaADVISORY
- usn.ubuntu.com/4522-1/nvdThird Party Advisory
- snyk.io/vuln/SNYK-JS-NOVNCNOVNC-469136ghsaWEB
- usn.ubuntu.com/4522-1ghsaWEB
- www.npmjs.com/advisories/1204ghsaWEB
- www.shielder.it/blog/exploiting-an-old-novnc-xss-cve-2017-18635-in-openstackghsaWEB
News mentions
0No linked articles in our index yet.