HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3079 | HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0 |
Github GHSA |
GHSA-37vq-hr2f-g7h7 | HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-10T20:14:07.250Z
Reserved: 2023-11-21T18:57:30.429Z
Link: CVE-2023-49093
Updated: 2024-08-02T21:46:28.698Z
Status : Modified
Published: 2023-12-04T05:15:07.430
Modified: 2024-11-21T08:32:48.503
Link: CVE-2023-49093
OpenCVE Enrichment
No data.
EUVD
Github GHSA