Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
{
"cpe": "cpe:2.3:a:mozilla:geckodriver:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.27.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}