CVE-2022-28109
15.04.2022, 16:15
Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary code (remote). The component is: WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is: Triggered by browsing to to a malicious remote web server. The WebDriver endpoint of Selenium Server (Grid) is vulnerable to DNS rebinding. This can be used to execute arbitrary code on the machine.
Vendor | Product | Version |
---|---|---|
selenium | selenium_grid | 𝑥 < 4.0.0 |
selenium | selenium_grid | 4.0.0 |
selenium | selenium_grid | 4.0.0:alpha1 |
selenium | selenium_grid | 4.0.0:alpha2 |
selenium | selenium_grid | 4.0.0:alpha3 |
selenium | selenium_grid | 4.0.0:alpha4 |
selenium | selenium_grid | 4.0.0:alpha5 |
selenium | selenium_grid | 4.0.0:alpha6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References