CVE Vulnerabilities

CVE-2023-49093

Published: Dec 04, 2023 | Modified: Dec 11, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
HIGH

HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0

Affected Software

Name Vendor Start Version End Version
Htmlunit Htmlunit * 3.9.0 (excluding)
Htmlunit Ubuntu bionic *
Htmlunit Ubuntu trusty *
Htmlunit Ubuntu xenial *

References