CVE-2020-5529

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/02/2020
Last modified:
15/10/2024

Description

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:htmlunit:htmlunit:*:*:*:*:*:*:*:* 2.37.0 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:a:apache:camel:-:*:*:*:*:*:*:*