MEDIUM6.1
GHSA-grh7-935j-hg6w
Cross-site Scripting in Sidekiq
Quick fix
GHSA-grh7-935j-hg6w — sidekiq: upgrade to the fixed version with the command below.
bundle update sidekiqDetails
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-30151[ADVISORY]
- https://github.com/mperham/sidekiq/issues/4852[WEB]
- https://github.com/mperham/sidekiq/commit/64f70339d1dcf50a55c00d36bfdb61d97ec63ed8[WEB]
- https://github.com/mperham/sidekiq[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html[WEB]