Junglewise Threat Intelligence

CVE-2017-18635: noVNC cross-site scripting via VNC server messages

CVE-2017-18635 · Severity: low · CVSS 3.1 · Published 2020-08-28

Vendors: npm.

Executive brief

noVNC is a browser-based VNC client that allows users to access remote desktops through a web interface. An attacker in control of a malicious VNC server can inject arbitrary HTML/JavaScript code into the noVNC web page by crafting malicious server messages, allowing them to execute code in the victim's browser and potentially steal session tokens or sensitive information. This affects any deployment using noVNC versions before 0.6.2.

Technical details

The vulnerability is a classic cross-site scripting (XSS) flaw caused by improper input validation of data received from the remote VNC server. Specifically, the noVNC client used the JavaScript `innerHTML` property to display status messages (including the VNC server name) without sanitization. An attacker controlling the remote VNC server could inject malicious HTML/JavaScript payloads in these messages, which would be executed in the context of the noVNC web page. The vulnerability affects users of include/ui.js and web pages vnc_auto.html and vnc.html. The fix, deployed in version 0.6.2 and commit 6048299, replaces unsafe `innerHTML` assignments with `textContent`, which treats input as plain text and prevents HTML injection. No user interaction beyond connecting to a malicious VNC server is required for exploitation.

Affected products

  • noVNC @novnc/novnc prior to 0.6.2

Timeline

  • 2017-01-12: disclosed: XSS vulnerability reported via GitHub issue #748
  • 2017-01-12: patched: Fix committed (6048299) switching innerHTML to textContent
  • 2017-01: patched: Version 0.6.2 released with fix
  • 2020-08-28: advisory: GitHub advisory GHSA-49rv-g7w5-m8xx published

References