MEDIUM 6.3 RubyGems

Resque vulnerable to Reflected Cross Site Scripting through pathnames

GHSA-r8xx-8vm8-x6wj · CVE-2023-50724

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

resque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint.

Patches

v2.1.0

Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

References

https://github.com/resque/resque/issues/1679
https://github.com/resque/resque/pull/1687

Ready to move

Start Securing

Free, no credit card | First findings in minutes