VDB
Sign up
HIGH8.3

GHSA-h3r8-h5qw-4r35

sidekiq vulnerable to cross-site scripting

Quick fix

GHSA-h3r8-h5qw-4r35 — sidekiq: upgrade to the fixed version with the command below.

bundle update sidekiq

Details

sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sidekiq
Introduced in: 7.0.4Fixed in: 7.0.8
Fixbundle update sidekiq

References