Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mh9-r3rr-9597

Опубликовано: 21 мая 2020
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Code execution vulnerability in HtmlUnit

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

Пакеты

Наименование

net.sourceforge.htmlunit:htmlunit

maven
Затронутые версииВерсия исправления

< 2.37.0

2.37.0

EPSS

Процентиль: 84%
0.02085
Низкий

8.1 High

CVSS3

Дефекты

CWE-665
CWE-94

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 6 лет назад

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

CVSS3: 5.6
redhat
почти 6 лет назад

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

CVSS3: 8.1
nvd
почти 6 лет назад

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

CVSS3: 8.1
debian
почти 6 лет назад

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. Html ...

EPSS

Процентиль: 84%
0.02085
Низкий

8.1 High

CVSS3

Дефекты

CWE-665
CWE-94