Vulnerabilities > Mozilla > Geckodriver

DATE CVE VULNERABILITY TITLE RISK
2022-05-02 CVE-2021-4138 Unspecified vulnerability in Mozilla Geckodriver
Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.
network
low complexity
mozilla
5.3
2021-07-20 CVE-2020-15660 Cross-Site Request Forgery (CSRF) vulnerability in Mozilla Geckodriver
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
network
low complexity
mozilla CWE-352
8.8