Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
References
| Link | Resource |
|---|---|
| https://github.com/mperham/sidekiq/issues/4852 | Exploit Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-04-06 06:15
Updated : 2021-04-09 18:42
NVD link : CVE-2021-30151
Mitre link : CVE-2021-30151
JSON object : View
Products Affected
contribsys
- sidekiq
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
