CVE-2022-28108 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Selenium Server (Grid) versions prior to 4, stemming from its acceptance of non-JSON content types. This high-severity vulnerability (CVSS 8.8) allows unauthenticated attackers to potentially achieve high impact on confidentiality, integrity, and availability through user interaction. While not currently on the KEV catalog, exploit modules for Remote Code Execution (RCE) via Chrome and Geckodriver are available in Metasploit, indicating a high potential for exploitation. Despite the availability of exploit code and a very high EPSS score, there is currently no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:selenium:selenium_grid:*:*:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:selenium:selenium_grid:4.0.0:-:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha1:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha2:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.