VDB
Sign up
MEDIUM6.1

GHSA-xv9c-mjw8-79gf

Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL

Quick fix

GHSA-xv9c-mjw8-79gf — sidekiq-cron: upgrade to the fixed version with the command below.

bundle update sidekiq-cron

Details

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sidekiq-cron
Introduced in: 0Fixed in: 2.4.0
Fixbundle update sidekiq-cron

References