First published: Mon May 02 2022(Updated: )
Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Geckodriver | <0.30.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4138 has a severity rating classified as moderate.
To fix CVE-2021-4138, upgrade to Geckodriver version 0.30.0 or later.
CVE-2021-4138 is a host header validation vulnerability.
CVE-2021-4138 affects users of Mozilla Geckodriver versions prior to 0.30.0.
Mitigation for CVE-2021-4138 involves enforcing proper host header checks and updating to a secure version.