CVE-2023-1892: Cross-site Scripting (XSS) - Reflected in sidekiq/sidekiq
Published Apr 5, 2023
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
Other sources
sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.
— GitHub
Affected Software
2 affected componentsFixes available
rubygems/sidekiq>=7.0.4<7.0.8
7.0.8
Contribsys Sidekiq>=7.0.4<7.0.8
Remediation
Event History
Apr 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Apr 21, 2023
Advisory Published
via GitHub·06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-1892?
The severity of CVE-2023-1892 is critical.
2
What is the affected software of CVE-2023-1892?
The affected software of CVE-2023-1892 is Contribsys Sidekiq version 7.0.4 to 7.0.8.
3
How can I fix CVE-2023-1892?
To fix CVE-2023-1892, it is recommended to update to Sidekiq version 7.0.8 or later.
4
What is the CWE ID of CVE-2023-1892?
The CWE ID of CVE-2023-1892 is 79.
5
Where can I find more information about CVE-2023-1892?
You can find more information about CVE-2023-1892 at the following references: [GitHub commit](https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214) and [Huntr.dev bounty](https://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777).