You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
mend-bolt-for-githubbot
changed the title
CVE-2023-26119 (High) detected in htmlunit-2.35.0.jar
CVE-2023-26119 (Critical) detected in htmlunit-2.35.0.jar
May 29, 2023
CVE-2023-26119 - Critical Severity Vulnerability
Vulnerable Library - htmlunit-2.35.0.jar
A headless browser intended for use in testing web-based applications.
Library home page: http://htmlunit.sourceforge.net
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/net/sourceforge/htmlunit/htmlunit/2.35.0/htmlunit-2.35.0.jar
Dependency Hierarchy:
Found in HEAD commit: 7d69c95a5145433319eabeefd4d4e15fc385b776
Found in base branch: develop
Vulnerability Details
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
Publish Date: 2023-04-03
URL: CVE-2023-26119
CVSS 3 Score Details (9.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2023-26119
Release Date: 2023-04-03
Fix Resolution: net.sourceforge.htmlunit:htmlunit:3.0.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: