{"id":"GHSA-h2rr-m97p-6jq9","summary":"Selenium Server (Grid) CSRF","details":"Selenium Server (Grid) before 4.0.0-alpha-7 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.","aliases":["CVE-2022-28108","PYSEC-2022-43167"],"modified":"2026-09-10T03:49:28.839291315Z","published":"2022-04-20T00:00:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-11-22T20:22:09Z","nvd_published_at":"2022-04-19T03:15:00Z","cwe_ids":["CWE-352"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28108"},{"type":"PACKAGE","url":"https://github.com/SeleniumHQ/selenium"},{"type":"WEB","url":"https://www.gabriel.urdhr.fr/2022/02/07/selenium-standalone-server-csrf-dns-rebinding-rce"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2022/02/07/3"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2022/04/14/2"},{"type":"WEB","url":"https://www.selenium.dev/downloads"}],"affected":[{"package":{"name":"org.seleniumhq.selenium:selenium-grid","ecosystem":"Maven","purl":"pkg:maven/org.seleniumhq.selenium/selenium-grid"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.0-alpha-7"}]}],"versions":["4.0.0-alpha-3","4.0.0-alpha-4","4.0.0-alpha-5","4.0.0-alpha-6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-h2rr-m97p-6jq9/GHSA-h2rr-m97p-6jq9.json"}},{"package":{"name":"org.seleniumhq.selenium:selenium-server","ecosystem":"Maven","purl":"pkg:maven/org.seleniumhq.selenium/selenium-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.0.0-alpha-2"}]}],"versions":["2.0.0","2.0a1","2.0a2","2.0a4","2.0a5","2.0a6","2.0a7","2.0b1","2.0b2","2.0b3","2.0rc2","2.0rc3","2.1.0","2.10.0","2.11.0","2.12.0","2.13.0","2.14.0","2.15.0","2.16.0","2.16.1","2.17.0","2.18.0","2.19.0","2.2.0","2.20.0","2.21.0","2.22.0","2.23.0","2.23.1","2.24.1","2.25.0","2.26.0","2.27.0","2.28.0","2.29.0","2.29.1","2.3.0","2.3.1","2.30.0","2.31.0","2.32.0","2.33.0","2.34.0","2.35.0","2.36.0","2.37.0","2.37.1","2.38.0","2.39.0","2.4.0","2.40.0","2.41.0","2.42.0","2.42.1","2.42.2","2.43.0","2.43.1","2.44.0","2.45.0","2.46.0","2.47.0","2.47.1","2.47.2","2.48.0","2.48.1","2.48.2","2.49.0","2.49.1","2.5.0","2.50.0","2.50.1","2.51.0","2.52.0","2.53.0","2.53.1","2.6.0","2.7.0","2.8.0","2.9.0","3.0.0","3.0.0-beta1","3.0.0-beta2","3.0.0-beta3","3.0.0-beta4","3.0.1","3.1.0","3.10.0","3.11.0","3.12.0","3.13.0","3.14.0","3.141.0","3.141.5","3.141.59","3.2.0","3.3.0","3.3.1","3.4.0","3.5.1","3.5.2","3.5.3","3.6.0","3.7.0","3.7.1","3.8.0","3.8.1","3.9.0","3.9.1","4.0.0-alpha-1","4.0.0-alpha-2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-h2rr-m97p-6jq9/GHSA-h2rr-m97p-6jq9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}