Tracker / CVE-2020-5529
CVE-2020-5529
High 8.1
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.
Affected products and versions
| apache | camel |
|---|---|
| canonical | ubuntu_linux |
| debian | debian_linux |
| htmlunit | htmlunit · … → 2.37.0 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.