Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5529

Опубликовано: 11 фев. 2020
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:htmlunit:htmlunit:*:*:*:*:*:*:*:*
Версия до 2.37.0 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
Конфигурация 4
cpe:2.3:a:apache:camel:-:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02085
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-665
CWE-94

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 6 лет назад

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

CVSS3: 5.6
redhat
почти 6 лет назад

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

CVSS3: 8.1
debian
почти 6 лет назад

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. Html ...

CVSS3: 8.1
github
больше 5 лет назад

Code execution vulnerability in HtmlUnit

EPSS

Процентиль: 84%
0.02085
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-665
CWE-94