CVE-2023-46950: XSS
Published Mar 1, 2024
·Updated
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.
Affected Software
3 affected componentsFixes available
Contribsys Sidekiq=6.5.8
rubygems/sidekiq-unique-jobs<7.1.33
7.1.33
rubygems/sidekiq-unique-jobs>=8.0.0<8.0.7
8.0.7
Event History
Mar 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-46950?
CVE-2023-46950 is rated as a high severity cross site scripting vulnerability.
2
How do I fix CVE-2023-46950?
To mitigate CVE-2023-46950, upgrade Sidekiq to version 6.5.9 or later, or upgrade the sidekiq-unique-jobs gem to version 8.0.7 or later.
3
What software is affected by CVE-2023-46950?
CVE-2023-46950 affects Contribsys Sidekiq version 6.5.8 and versions of the sidekiq-unique-jobs gem prior to 8.0.7.
4
Can CVE-2023-46950 lead to sensitive data exposure?
Yes, CVE-2023-46950 allows remote attackers to obtain sensitive information through crafted URLs.
5
Is there a workaround for CVE-2023-46950?
Disabling functionalities that utilize filter functions can serve as a temporary workaround until proper upgrades are applied.