First published: Tue Apr 06 2021(Updated: )
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/sidekiq | <5.2.0 | 5.2.0 |
redhat/sidekiq | <6.2.1 | 6.2.1 |
Sidekiq | <=5.1.3 | |
Sidekiq | >=6.0.0<=6.2.0 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30151 is a vulnerability in Sidekiq versions 5.1.3 and 6.x through 6.2.0 that allows XSS (Cross-Site Scripting) attacks via the queue name of the live-poll feature when Internet Explorer is used.
CVE-2021-30151 has a severity score of 6.1 (Medium).
Sidekiq versions 5.1.3 and 6.x through 6.2.0 are affected by CVE-2021-30151.
To mitigate CVE-2021-30151, update Sidekiq to version 5.2.0 or 6.2.1 depending on the affected version.
You can find more information about CVE-2021-30151 on the following references: [GitHub Advisory](https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2021-30151.yml), [Sidekiq Commit](https://github.com/mperham/sidekiq/commit/64f70339d1dcf50a55c00d36bfdb61d97ec63ed8), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2022:5498).