First published: Wed Apr 05 2023(Updated: )
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
rubygems/sidekiq | >=7.0.4<7.0.8 | 7.0.8 |
Sidekiq | >=7.0.4<7.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-1892 is critical.
The affected software of CVE-2023-1892 is Contribsys Sidekiq version 7.0.4 to 7.0.8.
To fix CVE-2023-1892, it is recommended to update to Sidekiq version 7.0.8 or later.
The CWE ID of CVE-2023-1892 is 79.
You can find more information about CVE-2023-1892 at the following references: [GitHub commit](https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214) and [Huntr.dev bounty](https://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777).