QID 376942
QID 376942: Selenium Server (Grid) Cross-Site Request Forgery (CSRF) Vulnerability
Selenium is a suite of tools for automating web browsers.
Affected Versions:
Selenium Server (Grid) before 4.x
QID Detection Logic(Unauthenticated):
This QID checks for the vulnerable versions of selenium-binary and selenium-wrapper.
it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.
Solution
To resolve this issue, upgrade to the latest versions Selenium Downlods
Vendor References
- GHSA-h2rr-m97p-6jq9 -
github.com/advisories/GHSA-h2rr-m97p-6jq9
CVEs related to QID 376942
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h2rr-m97p-6jq9 |
|