VYPR
High severity8.8NVD Advisory· Published Apr 19, 2022· Updated Jun 17, 2026

CVE-2022-28108

CVE-2022-28108

Description

Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.seleniumhq.selenium:selenium-gridMaven
< 4.0.0-alpha-74.0.0-alpha-7
org.seleniumhq.selenium:selenium-serverMaven
<= 4.0.0-alpha-2

Affected products

12
  • cpe:2.3:a:selenium:selenium_grid:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:selenium:selenium_grid:*:*:*:*:*:*:*:*range: <4.0.0
    • cpe:2.3:a:selenium:selenium_grid:4.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha4:*:*:*:*:*:*
    • cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha5:*:*:*:*:*:*
    • cpe:2.3:a:selenium:selenium_grid:4.0.0:alpha6:*:*:*:*:*:*
  • Selenium/Server (Grid)description
  • osv-coords3 versions
    < 3.3.6-r21+ 2 more
    • (no CPE)range: < 3.3.6-r21
    • (no CPE)range: < 4.0.0-alpha-7
    • (no CPE)range: <= 4.0.0-alpha-2

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.