QID 981485
QID 981485: Java (maven) Security Update for net.sourceforge.htmlunit:htmlunit (GHSA-5mh9-r3rr-9597)
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5mh9-r3rr-9597 for updates pertaining to this vulnerability.
Vendor References
- GHSA-5mh9-r3rr-9597 -
github.com/advisories/GHSA-5mh9-r3rr-9597
CVEs related to QID 981485
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5mh9-r3rr-9597 | net.sourceforge.htmlunit:htmlunit |
|