Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-67202

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 5.4

Описание

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

A flaw was found in Sidekiq-cron, an open-source scheduling add-on for Sidekiq. A remote attacker could exploit this cross-site scripting (XSS) vulnerability by injecting malicious scripts into a crafted URL. When this URL is rendered from cron.erb, the attacker's script would execute in the victim's browser, potentially leading to information disclosure or session hijacking.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the Sidekiq-cron web interface to trusted users and networks only. Implement firewall rules to limit access to the port on which Sidekiq-cron is exposed. Additionally, ensure that users accessing the interface are aware of phishing risks and avoid clicking untrusted links.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp21/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2467747sidekiq-cron: Sidekiq-cron: Cross-site scripting vulnerability via crafted URL

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
3 месяца назад

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

CVSS3: 6.1
github
3 месяца назад

Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL

5.4 Medium

CVSS3