CVE-2023-26156
Versions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system binary. This could lead to unauthorized access and potentially malicious actions on the host system. **Note:** An attacker must have access to the system running the vulnerable chromedriver library to exploit it. The success of exploitation also depends on the permissions and privileges of the process running chromedriver.
Published:Nov 9, 2023
Last Modified:Nov 21, 2024
EPS:Nov 9, 2023
EPSS Score:0.00473
CVSS Score:5.6
Affected Products
Vendor
Product
Action
Vendor
Chromedriver Project
Product
Chromedriver
Chromedriver Project
Chromedriver
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
