Описание
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
Ссылки
- ExploitIssue TrackingPatchThird Party Advisory
- Mailing ListThird Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.1.3 (включая)Версия от 6.0.0 (включая) до 6.2.0 (включая)
Одно из
cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*
cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.2396
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
ubuntu
почти 5 лет назад
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
CVSS3: 5.5
redhat
больше 4 лет назад
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
CVSS3: 6.1
debian
почти 5 лет назад
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue n ...
EPSS
Процентиль: 96%
0.2396
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79