RubySec

Providing security resources for the Ruby community

CVE-2023-1892 (sidekiq): sidekiq vulnerable to cross-site scripting

sidekiq vulnerable to cross-site scripting

Published: April 21, 2023

SECURITY IDENTIFIERS

GEM

sidekiq

SEVERITY

CVSS v3.x: 8.3 (High)

UNAFFECTED VERSIONS

< 7.0.4

PATCHED VERSIONS

>= 7.0.8

DESCRIPTION

sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.

RELATED