CVE-2020-15660

Name
CVE-2020-15660
Description
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/mozilla/geckodriver/releases/tag/v0.27.0
Mailing List http://www.openwall.com/lists/oss-security/2022/02/07/3

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mozilla:geckodriver:*:*:*:*:*:*:*:* geckodriver >= None < 0.27.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status