Vulnerability Description
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contribsys | Sidekiq | 6.5.8 |
Related Weaknesses (CWE)
References
- https://github.com/mhenrixon/sidekiq-unique-jobs/pull/829Issue Tracking
- https://github.com/mhenrixon/sidekiq-unique-jobs/releases/tag/v8.0.7Release Notes
- https://github.com/mhenrixon/sidekiq-unique-jobs/security/advisories/GHSA-cmh9-rExploitVendor Advisory
- https://link.orgPermissions Required
- https://www.link.comNot Applicable
- https://www.mgm-sp.com/cve/sidekiq-unique-jobs-reflected-xss-cve-2023-46950-cve-Third Party Advisory
- https://github.com/mhenrixon/sidekiq-unique-jobs/security/advisories/GHSA-cmh9-rExploitVendor Advisory
- https://link.orgPermissions Required
- https://www.link.comNot Applicable
FAQ
What is CVE-2023-46951?
CVE-2023-46951 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.
How severe is CVE-2023-46951?
CVE-2023-46951 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46951?
Check the references section above for vendor advisories and patch information. Affected products include: Contribsys Sidekiq.