HIGH
htmlunit: malicious JavaScript code leads to arbitrary java code execution
Published Feb 11, 2020
8.1
HIGHCVSS 3.1
EPSS 4.72%
Description
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.
Affected products
-
- Version prior to 2.37.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HtmlUnit Project | HtmlUnit | n/a |
|
Configuration 2
- 9.0
Configuration 3
- 16.04
No data.
Red Hat Single Sign-On 7
htmlunit
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Single Sign-On 7 | htmlunit | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (12)
- https://access.redhat.com/security/cve/CVE-2020-5529 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1803072 Issue Tracking
- https://github.com/HtmlUnit/htmlunit/commit/bc1f58d483cc8854a9c4c1739abd5e04a2eb0367
- https://github.com/HtmlUnit/htmlunit/releases/tag/2.37.0 x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://github.com/advisories/GHSA-5mh9-r3rr-9597 Advisory
- https://jvn.jp/en/jp/JVN34535327 third-party-advisoryx_refsource_JVNThird Party Advisory
- https://lists.apache.org/thread.html/ra2cd7f8e61dc6b8a2d9065094cd1f46aa63ad10f237ee363e26e8563%40%3Ccommits.camel.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ra2cd7f8e61dc6b8a2d9065094cd1f46aa63ad10f237ee363e26e8563@%3Ccommits.camel.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/08/msg00023.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-5529
- https://usn.ubuntu.com/4584-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-5529
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner jpcert
Published Feb 11, 2020
Updated Oct 15, 2024
Reserved Jan 6, 2020
Link CVE-2020-5529
CISA Vulnrichment
GHSA-5MH9-R3RR-9597 Updated Oct 15, 2024