HtmlUnit could be made to run programs as your login if it opened a malicious website.. ========================================================================== Ubuntu Security Notice USN-8220-1 May 05, 2026 htmlunit vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: HtmlUnit could be made to run programs as your login if it opened a malicious website. Software Description: - htmlunit: headless web browser written in Java Details: It was discovered that HtmlUnit was vulnerable to remote code execution via XSLT when browsing an attacker-controlled webpage. An attacker could possibly use this issue to execute arbitrary code in the context of the application using HtmlUnit. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libhtmlunit-java 2.8-3ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libhtmlunit-java 2.8-1ubuntu2.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8220-1 CVE-2023-49093 . HtmlUnit in Ubuntu could execute code as your login when accessing malicious sites. Immediate updates are required.. HtmlUnit Remote Code Execution Ubuntu Security Update. . Severity: Important. LinuxSecurity.com Team
It was discovered that HtmlUnit incorrectly initialized Rhino engine. An Attacker could possibly use this issue to execute arbitrary Java code (CVE-2020-5529). References: . MGASA-2021-0148 - Updated htmlunit packages fix security vulnerability Publication date: 21 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0148.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-5529 It was discovered that HtmlUnit incorrectly initialized Rhino engine. An Attacker could possibly use this issue to execute arbitrary Java code (CVE-2020-5529). References: - https://bugs.mageia.org/show_bug.cgi?id=27167 - https://ubuntu.com/security/notices/USN-4584-1 - https://www.cve.org/CVERecord?id=CVE-2020-5529 SRPMS: - 7/core/htmlunit-2.23-2.1.mga7 . CVE-2023-1234 vulnerability identified in HtmlUnit poses serious threat due to potential unauthorized Java code execution. Discover further details here.. HtmlUnit Security, Mageia Patch, Java Execution Risk. . Severity: Critical. LinuxSecurity.com Team
HtmlUnit could be made to crash or run programs as an administrator if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4584-1 October 15, 2020 htmlunit vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: HtmlUnit could be made to crash or run programs as an administrator if it opened a specially crafted file. Software Description: - htmlunit: headless web browser written in Java Details: It was discovered that HtmlUnit incorrectly initialized Rhino engine. An attacker could possibly use this issue to execute arbitrary Java code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libhtmlunit-java 2.8-1ubuntu2.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4584-1 CVE-2020-5529 Package Information: . Using HtmlUnit on Ubuntu may cause system instability or unauthorized command execution if launched without precautions. Always apply the latest security patches to protect against this risk. HtmlUnit Vulnerability, Ubuntu Security Notice, Java Security Issue. . Severity: Critical. LinuxSecurity.com Team
In HtmlUnit, a GUI-Less browser for Java programs, malicious JavaScript code was able to execute arbitrary Java code on the application. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2326-1
Get the latest Linux and open source security news straight to your inbox.