VDB
Sign up
MEDIUM6.3

GHSA-r8xx-8vm8-x6wj

Resque vulnerable to Reflected Cross Site Scripting through pathnames

Quick fix

GHSA-r8xx-8vm8-x6wj — resque: upgrade to the fixed version with the command below.

bundle update resque

Details

### Impact

resque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint.

### Patches

v2.1.0

### Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

### References https://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/resque
Introduced in: 0Fixed in: 2.1.0
Fixbundle update resque

References