NULL pointer dereference in Selenium - CVE-2023-5590
Published: April 30, 2025
Vulnerability identifier: #VU108090
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5590
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
Selenium
Splunk User Behavior Analytics (UBA)
IBM Observability with Instana
Rational Performance Tester
DevOps Test Performance
Splunk User Behavior Analytics (UBA)
IBM Observability with Instana
Rational Performance Tester
DevOps Test Performance
How to mitigate CVE-2023-5590
Cybersecurity Help is currently unaware of any official solution to address this vulnerability..
Selenium - update to 4.14.0
Splunk User Behavior Analytics (UBA) - update to 5.4.3
DevOps Test Performance - update to 11.0.7
IBM Observability with Instana - update to 1.0.293
Splunk User Behavior Analytics (UBA) - update to 5.4.3
DevOps Test Performance - update to 11.0.7
IBM Observability with Instana - update to 1.0.293