CVE-2023-1892
HIGH8.3EPSS 72.1%sidekiq vulnerable to cross-site scripting
Published: 4/21/2023Modified: 5/1/2024
Description
sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.
Affected packages (1)
- RubyGems/sidekiq>= 7.0.4, < 7.0.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-1892
- PATCHhttps://github.com/sidekiq/sidekiq
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2023-1892.yml
- WEBhttps://github.com/sidekiq/sidekiq/blob/main/Changes.md#708
- WEBhttps://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214
- WEBhttps://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777