CVE-2023-26119
🔴 Łataj teraz
Wykonanie zdalnego kodu w htmlunit umożliwia atakującemu przeglądanie jego strony.
CVSS
9.8
EPSS
2.5%
Exploit
poc
Vendor
htmlunit
Opis źródłowy (NVD)
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
exploit rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 2.5% |
| Opublikowano (NVD) | 2023-04-03 05:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:23 UTC |
Referencje
- https://github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956b ([email protected]) [Patch]
- https://security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500 ([email protected]) [Third Party Advisory]
- https://siebene.github.io/2022/12/30/HtmlUnit-RCE/ ([email protected]) [Exploit, Third Party Advisory]