Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5590

Опубликовано: 16 окт. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

A null pointer dereference flaw was found in Selenium IEDriver. This issue causes the driver to crash when selenium gets the cookies from an attacker controlled page, which could leave the application unavailable.

Отчет

Successful exploitation of this issue depends on the IE Driver being used and also available to the external malicious user to redirect to a malicious page in order to consume a malicious cookie that may crash the environment. Therefore, this flaw is rated as having a Moderate impact. Red Hat Single Sign-On uses part of the integration tests only, therefore, it is rated as a Low impact.

Меры по смягчению последствий

No mitigation is currently known for the IE Driver. If possible, opt for another browser driver.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7seleniumNot affected
Red Hat build of Apicurio Registry 2seleniumNot affected
Red Hat Decision Manager 7seleniumNot affected
Red Hat Fuse 7seleniumNot affected
Red Hat Integration Camel K 1seleniumNot affected
Red Hat Integration Camel Quarkus 2seleniumNot affected
Red Hat JBoss Data Grid 7seleniumOut of support scope
Red Hat JBoss Enterprise Application Platform 6seleniumOut of support scope
Red Hat JBoss Enterprise Application Platform 7seleniumNot affected
Red Hat JBoss Enterprise Application Platform 8seleniumNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2244345selenium: potential null pointer access in CookieManager

EPSS

Процентиль: 30%
0.00114
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

CVSS3: 7.5
github
больше 2 лет назад

NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

EPSS

Процентиль: 30%
0.00114
Низкий

7.5 High

CVSS3