Описание
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
A reflected Cross-site Scripting (XSS) vulnerability was found in sidekiq. This issue may allow code to be executed via multiples endpoints in the GET parameter "period".
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Satellite 6 | rubygem-gitlab-sidekiq-fetcher | Not affected | ||
| Red Hat Satellite 6 | rubygem-sidekiq | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2188630sidekiq: Reflected XSS on Sidekiq through multiples endpoints via GET parameter "period" in sidekiq/sidekiq
9.6 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.6
ubuntu
почти 3 года назад
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVSS3: 9.6
nvd
почти 3 года назад
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVSS3: 9.6
debian
почти 3 года назад
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/si ...
9.6 Critical
CVSS3