Description
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-7647 | Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution. |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T13:22:30.616Z
Reserved: 2020-07-10T00:00:00.000Z
Link: CVE-2020-15660
No data.
Status : Modified
Published: 2021-07-20T12:15:07.657
Modified: 2024-11-21T05:05:57.900
Link: CVE-2020-15660
OpenCVE Enrichment
No data.
Weaknesses
EUVD