Lucene search

K
osvGoogleOSV:CVE-2022-28108
HistoryApr 19, 2022 - 3:15 a.m.

CVE-2022-28108

2022-04-1903:15:08
Google
osv.dev
3
selenium server
csrf
vulnerability fix
non-json content types

AI Score

7

Confidence

High

EPSS

0.002

Percentile

57.6%

Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.

AI Score

7

Confidence

High

EPSS

0.002

Percentile

57.6%