HIGH8.3
GHSA-h3r8-h5qw-4r35
sidekiq vulnerable to cross-site scripting
Quick fix
GHSA-h3r8-h5qw-4r35 — sidekiq: upgrade to the fixed version with the command below.
bundle update sidekiqDetails
sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-1892[ADVISORY]
- https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2023-1892.yml[WEB]
- https://github.com/sidekiq/sidekiq[PACKAGE]
- https://github.com/sidekiq/sidekiq/blob/main/Changes.md#708[WEB]
- https://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777[WEB]