Lucene search

K
redhatcveRedhat.comRH:CVE-2019-0542
HistoryApr 07, 2020 - 5:01 p.m.

CVE-2019-0542

2020-04-0717:01:16
redhat.com
access.redhat.com
12

0.027 Low

EPSS

Percentile

90.5%

It was found that xterm.js does not sanitize terminal escape sequences in browser terminals allowing for execution of arbitrary commands. An attacker could exploit this by convincing a user with a xterm.js browser terminal to display an escape sequence by, for example, reading a from a log file containing attacker-controlled input.