HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
{
"priority_reason": "This is a vulnerability that can be triggered remotely and leads to code execution. A PoC has been made available.",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.8-1ubuntu2.1+esm1",
"binary_name": "libhtmlunit-java"
}
]
}
{
"priority_reason": "This is a vulnerability that can be triggered remotely and leads to code execution. A PoC has been made available.",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.8-3ubuntu1+esm1",
"binary_name": "libhtmlunit-java"
}
]
}