PT-2022-18814 · Selenium · Selenium Grid+2
Gabriel Corona
·
Published
2022-04-15
·
Updated
2022-04-25
·
CVE-2022-28109
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Selenium Selenium Grid (formerly Selenium Standalone Server) versions prior to 4.0.0-alpha-7
Description
The issue is related to DNS rebinding, which can be used to execute arbitrary code on the machine. The component affected is the WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is triggered by browsing to a malicious remote web server. This allows for the execution of arbitrary code remotely.
Recommendations
For versions prior to 4.0.0-alpha-7, update to version 4.0.0-alpha-7 or later to resolve the issue.
As a temporary workaround, consider restricting access to the WebDriver endpoint of Selenium Server (Grid) to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Selenium
Selenium Grid
Selenium Standalone Server