PT-2022-18814 · Selenium · Selenium Grid+2

Gabriel Corona

·

Published

2022-04-15

·

Updated

2022-04-25

·

CVE-2022-28109

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Selenium Selenium Grid (formerly Selenium Standalone Server) versions prior to 4.0.0-alpha-7
Description The issue is related to DNS rebinding, which can be used to execute arbitrary code on the machine. The component affected is the WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is triggered by browsing to a malicious remote web server. This allows for the execution of arbitrary code remotely.
Recommendations For versions prior to 4.0.0-alpha-7, update to version 4.0.0-alpha-7 or later to resolve the issue. As a temporary workaround, consider restricting access to the WebDriver endpoint of Selenium Server (Grid) to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28109

Affected Products

Selenium
Selenium Grid
Selenium Standalone Server