CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS
Percentile
90.6%
sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.
github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2023-1892.yml
github.com/sidekiq/sidekiq
github.com/sidekiq/sidekiq/blob/main/Changes.md#708
github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214
huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777
nvd.nist.gov/vuln/detail/CVE-2023-1892