chromedriver@2.23.1 vulnerabilities

ChromeDriver for Selenium

  • latest version

    131.0.3

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the chromedriver package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Command Injection

    chromedriver is a ChromeDriver for Selenium

    Affected versions of this package are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system binary. This could lead to unauthorized access and potentially malicious actions on the host system.

    Note:

    An attacker must have access to the system running the vulnerable chromedriver library to exploit it. The success of exploitation also depends on the permissions and privileges of the process running chromedriver.

    How to fix Command Injection?

    Upgrade chromedriver to version 119.0.1 or higher.

    <119.0.1
    • H
    Resources Downloaded over Insecure Protocol

    chromedriver is a ChromeDriver for Selenium. Affected versions of the package are vulnerable to Man in the Middle (MitM) attacks due to downloading resources over an insecure protocol.

    How to fix Resources Downloaded over Insecure Protocol?

    Upgrade to version 2.25.2 or higher.

    <2.25.2