HIGH 8.3 RubyGems
sidekiq vulnerable to cross-site scripting
GHSA-h3r8-h5qw-4r35 · CVE-2023-1892
Published · Modified
Description
sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-1892
- WEB https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214
- WEB https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2023-1892.yml
- PACKAGE https://github.com/sidekiq/sidekiq
- WEB https://github.com/sidekiq/sidekiq/blob/main/Changes.md#708
- WEB https://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777
Ready to move
Start Securing
Free, no credit card | First findings in minutes