PT-2022-7706 · Selenium · Selenium Server

Published

2022-02-07

·

Updated

2022-04-27

·

CVE-2022-28108

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Selenium Server (Grid) versions prior to 4
Description The issue is related to a CSRF vulnerability in the Selenium Server (Grid) tool. It allows non-JSON content types, such as application/x-www-form-urlencoded, multipart/form-data, and text/plain, which can be exploited by a remote attacker to perform a CSRF attack.
Recommendations For versions prior to 4, update to version 4 or later to resolve the issue. As a temporary workaround, consider restricting the permitted content types to JSON only to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00929
CVE-2022-28108
GHSA-H2RR-M97P-6JQ9
PYSEC-2022-43167

Affected Products

Selenium Server