QID 730603
Date Published: 2022-08-30
QID 730603: Selenium Server (Grid) Domain Name System (DNS) Rebinding Remote Code Execution (RCE) Vulnerability (GHSA-r2fp-xp6r-99gj)
Selenium is a suite of tools for automating web browsers.
Affected Versions:
Selenium Server (Grid) before 4.0.0-alpha-7
QID Detection Logic(Unauthenticated):
This QID checks for the vulnerable versions of selenium-binary via a POST request to graphql endpoint.
The WebDriver endpoint of Selenium Server (Grid) is vulnerable to DNS rebinding. This can be used to execute arbitrary code on the machine.
Solution
To resolve this issue, upgrade to the latest versions Selenium Downloads
Workaround:
Please follow the steps mentioned to apply mitigation Mitigation for Selenium Server (Grid)
Vendor References
- GHSA-r2fp-xp6r-99gj -
github.com/advisories/GHSA-r2fp-xp6r-99gj
CVEs related to QID 730603
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r2fp-xp6r-99gj |
|