VDB
Sign up
MEDIUM6.3

GHSA-r9mq-m72x-257g

Resque vulnerable to reflected XSS in Queue Endpoint

Quick fix

GHSA-r9mq-m72x-257g — resque: upgrade to the fixed version with the command below.

bundle update resque

Details

### Impact

Reflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web.

### Patches

v2.6.0

### Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

### References

https://github.com/resque/resque/pull/1865

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/resque
Introduced in: 0Fixed in: 2.6.0
Fixbundle update resque

References