{"id":"CVE-2020-5529","details":"HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.","aliases":["GHSA-5mh9-r3rr-9597"],"modified":"2026-07-08T05:57:06.253775744Z","published":"2020-02-11T12:15:21.210Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"16.04"},{"last_affected":"16.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*"]},{"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/ra2cd7f8e61dc6b8a2d9065094cd1f46aa63ad10f237ee363e26e8563%40%3Ccommits.camel.apache.org%3E"},{"type":"ADVISORY","url":"https://github.com/HtmlUnit/htmlunit/releases/tag/2.37.0"},{"type":"ADVISORY","url":"https://jvn.jp/en/jp/JVN34535327/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00023.html"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4584-1/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/htmlunit/htmlunit","events":[{"introduced":"0"},{"fixed":"cb286216471036d314897083f5aee48039c51e50"}],"database_specific":{"cpe":"cpe:2.3:a:htmlunit:htmlunit:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.37.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.36.0","2.35.0","2.34.1","2.34.0","2.33","2.32"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5529.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}