VDB
Sign up
MEDIUM6.3

GHSA-gc3j-vvwf-4rp8

Resque vulnerable to reflected XSS in resque-web failed and queues lists

Quick fix

GHSA-gc3j-vvwf-4rp8 — resque: upgrade to the fixed version with the command below.

bundle update resque

Details

### Impact

The following paths in resque-web have been found to be vulnerable to reflected XSS:

``` /failed/?class=<script>alert(document.cookie)</script> /queues/><img src=a onerror=alert(document.cookie)> ```

### Patches

v2.2.1

### Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

### References

https://github.com/resque/resque/pull/1790

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/resque
Introduced in: 0Fixed in: 2.2.1
Fixbundle update resque

References