Description
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2943-1 | ruby-sidekiq security update |
Debian DLA |
DLA-3360-1 | ruby-sidekiq security update |
Debian DLA |
DLA-4407-1 | ruby-sidekiq security update |
Github GHSA |
GHSA-grh7-935j-hg6w | Cross-site Scripting in Sidekiq |
Ubuntu USN |
USN-7695-1 | Sidekiq vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T22:24:59.859Z
Reserved: 2021-04-06T00:00:00.000Z
Link: CVE-2021-30151
No data.
Status : Modified
Published: 2021-04-06T06:15:15.547
Modified: 2024-11-21T06:03:24.160
Link: CVE-2021-30151
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA
Ubuntu USN