Описание
HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
A flaw was found in HTMLUnit. Fetching external resources may be possible for XSLT processors with the Feature for Secure Processing disabled (FSP), allowing code injection and arbitrary code execution. HTMLUnit is vulnerable to this type of attack by default.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Applications 6 | net.sourceforge.htmlunit-htmlunit-jar | Will not fix | ||
| Migration Toolkit for Runtimes | net.sourceforge.htmlunit-htmlunit-jar | Will not fix | ||
| Red Hat Build of Keycloak | net.sourceforge.htmlunit-htmlunit-jar | Not affected | ||
| Red Hat build of Quarkus | net.sourceforge.htmlunit/htmlunit | Not affected | ||
| Red Hat Data Grid 8 | net.sourceforge.htmlunit-htmlunit-jar | Not affected | ||
| Red Hat Decision Manager 7 | net.sourceforge.htmlunit-htmlunit-jar | Not affected | ||
| Red Hat Fuse 7 | net.sourceforge.htmlunit-htmlunit-jar | Fix deferred | ||
| Red Hat Integration Camel K 1 | net.sourceforge.htmlunit-htmlunit-jar | Not affected | ||
| Red Hat Integration Camel Quarkus 2 | net.sourceforge.htmlunit-htmlunit-jar | Not affected | ||
| Red Hat JBoss Data Grid 7 | net.sourceforge.htmlunit-htmlunit-jar | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerab ...
HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL
Уязвимость браузера без графической оболочки HtmlUnit, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3