QID 730602
Date Published: 2022-08-30
QID 730602: Selenium Server (Grid) Cross-Site Request Forgery (CSRF) Vulnerability (GHSA-h2rr-m97p-6jq9)
Selenium is a suite of tools for automating web browsers.
Affected Versions:
Selenium Server (Grid) before 4.x
QID Detection Logic(Unauthenticated):
This QID checks for the vulnerable versions of selenium-binary via a POST request to graphql endpoint.
it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.
Solution
To resolve this issue, upgrade to the latest versions Selenium Downloads
Workaround:
Please follow the steps mentioned to apply mitigation Mitigation for Selenium Server (Grid)
Vendor References
- GHSA-h2rr-m97p-6jq9 -
github.com/advisories/GHSA-h2rr-m97p-6jq9
CVEs related to QID 730602
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h2rr-m97p-6jq9 |
|