Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
noVNC 安全漏洞
Vulnerability Description
noVNC是软件开发者Joel Martin所研发的一款使用了HTML5 Canvas(用于绘制图像的HTML5标签)和WebSockets(HTML5通信功能)的基于浏览器的VNC(远程控制工具软件)客户端。 noVNC 0.5之前版本中存在安全漏洞,该漏洞源于程序没有为https会话中的cookie设置安全标志。攻击者可通过拦截https会话的传输利用该漏洞捕获cookie。
CVSS Information
N/A
Vulnerability Type
N/A