HtmlUnit / htmlunit-neko

HtmlUnit adaptation of NekoHtml
Apache License 2.0
17 stars 13 forks source link

Question about htmlunit CVEs and neko-htmlunit and CVE-2023-49093 #75

Closed wojteo closed 8 months ago

wojteo commented 8 months ago

Hi, is neko-htmlunit affected by CVE-2023-49093?

I never know if CVEs for htmlunit applies to neko or not. Should I assume that they always do? Is there a reason why CPEs do not point to neko?

rbri commented 8 months ago

@wojteo sorry for the confusion and maybe all the missing details in the HtmlUnit documentation.

  1. neko is not effected by CVE-2023-49093
  2. i try to document the neko related CVE's in the neko readme (https://github.com/HtmlUnit/htmlunit-neko)
  3. CVE-2023-49093 was fixed with https://github.com/HtmlUnit/htmlunit/commit/e015082aa909fd9e1c2b5f9b26553ddc0ddbbcab

Hope that helps

wojteo commented 8 months ago

Thank you :)