Cryptographic issues in noVNC - CVE-2013-7436

 

Cryptographic issues in noVNC - CVE-2013-7436

Published: April 10, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40842
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-7436
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.


Affected software

noVNC
Fedora
novnc

How to mitigate CVE-2013-7436

Install update from vendor's website.

novnc - addressed in versions 0.5.1-2.el6, 0.5.1-2.el7

External References

Related Security Bulletins