CVE-2020-5529
https://notcve.org/view.php?id=CVE-2020-5529
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application. HtmlUnit anterior a 2.37.0, contiene vulnerabilidades de ejecución de código. HtmlUnit inicializa el motor Rhino inapropiadamente, por lo tanto, un código JavScript malicioso puede ejecutar código Java arbitrario en la aplicación. • https://github.com/HtmlUnit/htmlunit/releases/tag/2.37.0 https://jvn.jp/en/jp/JVN34535327 https://lists.apache.org/thread.html/ra2cd7f8e61dc6b8a2d9065094cd1f46aa63ad10f237ee363e26e8563%40%3Ccommits.camel.apache.org%3E https://lists.debian.org/debian-lts-announce/2020/08/msg00023.html https://usn.ubuntu.com/4584-1 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-665: Improper Initialization •