ADVISORIES
GEM
SEVERITY
CVSS v3.x: 8.3 (High)
UNAFFECTED VERSIONS
- < 7.0.4
PATCHED VERSIONS
- >= 7.0.8
DESCRIPTION
sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.
RELATED
- https://nvd.nist.gov/vuln/detail/CVE-2023-1892
- https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214
- https://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777
- https://github.com/sidekiq/sidekiq/blob/main/Changes.md#708
- https://github.com/advisories/GHSA-h3r8-h5qw-4r35