9.8
CVSSv3

CVE-2023-26119

Published: 03/04/2023 Updated: 07/12/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and prior to 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

htmlunit htmlunit

Github Repositories

Demo app Swagger URL: localhost:8080/swagger-ui/indexhtml TODO: Update Spring Boot Starter Parent 314 ASAP to fix vulnerabilities from dependencies: CVE-2023-33264 CVE-2023-26119 CVE-2022-45868 CVE-2022-1471 More info: mvnrepositorycom/artifact/orgspringframeworkboot/spring-boot-starter-parent/314