CVE-2022-28108
19.04.2022, 03:15
Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.
Vendor | Product | Version |
---|---|---|
selenium | selenium_grid | 𝑥 < 4.0.0 |
selenium | selenium_grid | 4.0.0 |
selenium | selenium_grid | 4.0.0:alpha1 |
selenium | selenium_grid | 4.0.0:alpha2 |
selenium | selenium_grid | 4.0.0:alpha3 |
selenium | selenium_grid | 4.0.0:alpha4 |
selenium | selenium_grid | 4.0.0:alpha5 |
selenium | selenium_grid | 4.0.0:alpha6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References