PT-2023-10141 · Lukehutch · Gribbit

·

CVE-2014-125071

·

Published

2023-01-09

·

Updated

2024-05-17

CVSS v2.0

5.2

Medium

VectorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions lukehutch Gribbit (affected versions not specified)
Description A problematic issue was found in lukehutch Gribbit, affecting the messageReceived function of the file src/gribbit/request/HttpRequestHandler.java. This issue leads to missing origin validation in websockets.
Recommendations Apply a patch to fix this issue, specifically the patch named 620418df247aebda3dd4be1dda10fe229ea505dd. As a temporary workaround, consider disabling the messageReceived function until a patch is available. Restrict access to the vulnerable HttpRequestHandler.java file to minimize the risk of exploitation.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-125071

Affected Products

Gribbit