CVE-2019-0542

EUVD-2019-0189
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
xtermjsxterm.js
𝑥
< 5.0.0
redhatopenshift_container_platform
3.9 ≤
𝑥
< 3.9.99
redhatopenshift_container_platform
3.10 ≤
𝑥
< 3.10.163
redhatopenshift_container_platform
3.11 <
𝑥
< 3.11.104
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-xterm
bookworm
3.8.1+~cs0.9.0-1
fixed
bullseye
3.8.1+~cs0.9.0-1
fixed
sid
5.3.0-3
fixed
trixie
5.3.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-xterm
bionic
not-affected
cosmic
ignored
disco
not-affected
trusty
dne
xenial
dne