HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
0Unknown introduced version / All previous versions are affected
Affected versions
2.*
2.8-1ubuntu2
2.8-1ubuntu2.1
Ecosystem specific
{
"ubuntu_priority": "high",
"priority_reason": "This is a vulnerability that can be triggered remotely and leads to code execution. A PoC has been made available."
}
0Unknown introduced version / All previous versions are affected
Affected versions
2.*
2.8-2ubuntu1
2.8-3ubuntu1
Ecosystem specific
{
"ubuntu_priority": "high",
"priority_reason": "This is a vulnerability that can be triggered remotely and leads to code execution. A PoC has been made available."
}