6.8
CVSSv2

CVE-2019-0542

Published: 09/01/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xtermjs xterm.js

redhat openshift container platform

Vendor Advisories

Debian Bug report logs - #926670 CVE-2019-0542 Package: src:node-xterm; Maintainer for src:node-xterm is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 8 Apr 2019 18:57:02 UTC Severity: grave Tags: fixed-upstream, security, up ...
Synopsis Moderate: OpenShift Container Platform 311 atomic-openshift-web-console security update Type/Severity Security Advisory: Moderate Topic An update for atomic-openshift-web-console is now available for Red Hat Openshift Container Platform 311Red Hat Product Security has rated this update as having ...
Synopsis Moderate: OpenShift Container Platform 39 atomic-openshift-web-console security update Type/Severity Security Advisory: Moderate Topic An update for atomic-openshift-web-console is now available for Red Hat OpenShift Container Platform 39Red Hat Product Security has rated this update as having a ...
Synopsis Moderate: OpenShift Container Platform 310 atomic-openshift-web-console security update Type/Severity Security Advisory: Moderate Topic An update for atomic-openshift-web-console is now available for Red Hat OpenShift Container Platform 310Red Hat Product Security has rated this update as having ...
It was found that xtermjs does not sanitize terminal escape sequences in browser terminals allowing for execution of arbitrary commands An attacker could exploit this by convincing a user with a xtermjs browser terminal to display an escape sequence by, for example, reading a from a log file containing attacker-controlled input ...