Skip to content

v0.6.2

Compare
Choose a tag to compare
@DirectXMan12 DirectXMan12 released this 12 Jan 19:54
· 2 commits to stable/v0.6 since this release

_This is a vulnerability fix release._

Fixes a XSS issue in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

This affects users of vnc_auto.html and vnc.html, as well as any users of include/ui.js.

Thanks to David Wyde of Cisco for reporting the issue.