CVE-2020-15660 - log back

CVE-2020-15660 edited at 20 Jul 2021 15:46:02
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site request forgery
Description
+ Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a cross-site request forgery (CSRF) vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
References
+ https://github.com/mozilla/geckodriver/releases/tag/v0.27.0
Notes
CVE-2020-15660 created at 20 Jul 2021 15:44:01