MEDIUM 6.3 RubyGems

Resque vulnerable to reflected XSS in Queue Endpoint

GHSA-r9mq-m72x-257g · CVE-2023-50727

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Reflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web.

Patches

v2.6.0

Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

References

https://github.com/resque/resque/pull/1865

Ready to move

Start Securing

Free, no credit card | First findings in minutes