
SeleniumGreed: The RCE That Was Always There
TL;DR
Every Selenium Grid instance deployed with Firefox nodes is vulnerable to unauthenticated remote code execution. Not “was” - is. The …
Read More
7 min read

Every Selenium Grid instance deployed with Firefox nodes is vulnerable to unauthenticated remote code execution. Not “was” - is. The …

On the 28th of October the exploit for CVE-2023-20198 was released by
SECUINFRA after
being captured on one of their honeypots.
While it enables full …

Update 2023-11-03: The issue has been fixed in version 7.2.
At LeakIX we analyse new vulnerabilities discovered by other …