Описание
sidekiq vulnerable to cross-site scripting
sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-1892
- https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2023-1892.yml
- https://github.com/sidekiq/sidekiq/blob/main/Changes.md#708
- https://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777
Пакеты
Наименование
sidekiq
rubygems
Затронутые версииВерсия исправления
>= 7.0.4, < 7.0.8
7.0.8
Связанные уязвимости
CVSS3: 9.6
ubuntu
почти 3 года назад
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVSS3: 9.6
redhat
почти 3 года назад
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVSS3: 9.6
nvd
почти 3 года назад
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVSS3: 9.6
debian
почти 3 года назад
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/si ...