CVE-2021-4138: Medium severity mozilla geckodriver vulnerability
Published May 2, 2022
·Updated
Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.
Affected Software
1 affected component
Mozilla Geckodriver<0.30.0
Event History
May 2, 2022
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-4138?
CVE-2021-4138 has a severity rating classified as moderate.
2
How do I fix CVE-2021-4138?
To fix CVE-2021-4138, upgrade to Geckodriver version 0.30.0 or later.
3
What type of vulnerability is CVE-2021-4138?
CVE-2021-4138 is a host header validation vulnerability.
4
Who is affected by CVE-2021-4138?
CVE-2021-4138 affects users of Mozilla Geckodriver versions prior to 0.30.0.
5
What mitigation is available for CVE-2021-4138?
Mitigation for CVE-2021-4138 involves enforcing proper host header checks and updating to a secure version.