CVE-2021-30151: XSS
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/sidekiqto a version that resolves this vulnerability.Fixed in 5.2.0 - Upgrade
Upgrade
redhat/sidekiqto a version that resolves this vulnerability.Fixed in 6.2.1
Event History
Frequently Asked Questions
What is CVE-2021-30151?
CVE-2021-30151 is a vulnerability in Sidekiq versions 5.1.3 and 6.x through 6.2.0 that allows XSS (Cross-Site Scripting) attacks via the queue name of the live-poll feature when Internet Explorer is used.
How severe is CVE-2021-30151?
CVE-2021-30151 has a severity score of 6.1 (Medium).
Which software versions are affected by CVE-2021-30151?
Sidekiq versions 5.1.3 and 6.x through 6.2.0 are affected by CVE-2021-30151.
How can I mitigate CVE-2021-30151?
To mitigate CVE-2021-30151, update Sidekiq to version 5.2.0 or 6.2.1 depending on the affected version.
Where can I find more information about CVE-2021-30151?
You can find more information about CVE-2021-30151 on the following references: [GitHub Advisory](https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2021-30151.yml), [Sidekiq Commit](https://github.com/mperham/sidekiq/commit/64f70339d1dcf50a55c00d36bfdb61d97ec63ed8), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2022:5498).