{"id":"CVE-2022-28108","details":"Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.","aliases":["GHSA-h2rr-m97p-6jq9","PYSEC-2022-43167"],"modified":"2026-04-10T15:29:15.221814362Z","published":"2022-04-19T03:15:08.740Z","related":["CGA-94vf-58w3-5mv5"],"references":[{"type":"ADVISORY","url":"https://www.selenium.dev/downloads/"},{"type":"ADVISORY","url":"https://www.openwall.com/lists/oss-security/2022/02/07/3"},{"type":"EVIDENCE","url":"https://www.gabriel.urdhr.fr/2022/02/07/selenium-standalone-server-csrf-dns-rebinding-rce/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/seleniumhq/selenium","events":[{"introduced":"0"},{"fixed":"3a2181467904af9043828cede13e5dc866c1af12"},{"introduced":"0"},{"last_affected":"3a2181467904af9043828cede13e5dc866c1af12"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"4.0.0"},{"introduced":"0"},{"last_affected":"4.0.0-NA"}]}}],"versions":["2.34.0","android-froyo","atoms-base-20170918","atoms-base-20181002","ide-1.0.11","selenium-2.0-alpha-1","selenium-2.0-alpha-2","selenium-2.0-alpha-3","selenium-2.0-alpha-4","selenium-2.0-alpha-5","selenium-2.0-alpha-6","selenium-2.0-alpha-7","selenium-2.0-beta-1","selenium-2.0-beta-2","selenium-2.0-beta-3","selenium-2.0-rc-2","selenium-2.0-rc-3","selenium-2.0-rc1","selenium-2.0.0","selenium-2.1.0","selenium-2.10.0","selenium-2.11.0","selenium-2.12.0","selenium-2.13.0","selenium-2.14.0","selenium-2.15.0","selenium-2.16.0","selenium-2.17.0","selenium-2.18.0","selenium-2.19.0","selenium-2.2.0","selenium-2.20.0","selenium-2.21.0","selenium-2.22.0","selenium-2.23.0","selenium-2.23.1","selenium-2.24.1","selenium-2.25.0","selenium-2.26.0","selenium-2.27.0","selenium-2.28.0","selenium-2.29.0","selenium-2.29.0a","selenium-2.3.0","selenium-2.30.0","selenium-2.31.0","selenium-2.32.0","selenium-2.35.0","selenium-2.36.0","selenium-2.37.0","selenium-2.38.0","selenium-2.39.0","selenium-2.4.0","selenium-2.40.0","selenium-2.41.0","selenium-2.42.0","selenium-2.42.1","selenium-2.42.2","selenium-2.43.0","selenium-2.43.1","selenium-2.44.0","selenium-2.45.0","selenium-2.46.0","selenium-2.47.0","selenium-2.47.1","selenium-2.48.0","selenium-2.48.2","selenium-2.49.0","selenium-2.49.1","selenium-2.5.0","selenium-2.50.0","selenium-2.50.1","selenium-2.51.0","selenium-2.52.0","selenium-2.52.1","selenium-2.52.2","selenium-2.53.0","selenium-2.6.0","selenium-2.7.0","selenium-2.8.0","selenium-2.9.0","selenium-3.0.0","selenium-3.0.0-beta-1","selenium-3.0.0-beta-2","selenium-3.0.0-beta-3","selenium-3.0.0-beta-4","selenium-3.0.1","selenium-3.1.0","selenium-3.10.0","selenium-3.11.0","selenium-3.12.0","selenium-3.13.0","selenium-3.14.0","selenium-3.141.0","selenium-3.141.5","selenium-3.141.59","selenium-3.150.0","selenium-3.2.0","selenium-3.3.0","selenium-3.3.1","selenium-3.4.0","selenium-3.5.0","selenium-3.5.1","selenium-3.5.2","selenium-3.5.3","selenium-3.6.0","selenium-3.7.0","selenium-3.7.1","selenium-3.8.0","selenium-3.8.1","selenium-3.9.0","selenium-3.9.1","selenium-4.0.0","selenium-4.0.0-alpha-1","selenium-4.0.0-alpha-2","selenium-4.0.0-alpha-3","selenium-4.0.0-alpha-4","selenium-4.0.0-alpha-5","selenium-4.0.0-alpha-6","selenium-4.0.0-beta-1","selenium-4.0.0-beta-2","selenium-4.0.0-beta-3","selenium-4.0.0-beta-4","selenium-4.0.0-rc-1","selenium-4.0.0-rc-2","selenium-4.0.0-rc-3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28108.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"4.0.0-alpha1"}]},{"events":[{"introduced":"0"},{"last_affected":"4.0.0-alpha2"}]},{"events":[{"introduced":"0"},{"last_affected":"4.0.0-alpha3"}]},{"events":[{"introduced":"0"},{"last_affected":"4.0.0-alpha4"}]},{"events":[{"introduced":"0"},{"last_affected":"4.0.0-alpha5"}]},{"events":[{"introduced":"0"},{"last_affected":"4.0.0-alpha6"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}