{"id":"GHSA-h3r8-h5qw-4r35","summary":"sidekiq vulnerable to cross-site scripting ","details":"sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.","aliases":["CVE-2023-1892"],"modified":"2024-05-01T13:31:16.043478Z","published":"2023-04-21T06:30:19Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-04-24T20:20:49Z","nvd_published_at":"2023-04-21T05:15:07Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1892"},{"type":"WEB","url":"https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2023-1892.yml"},{"type":"PACKAGE","url":"https://github.com/sidekiq/sidekiq"},{"type":"WEB","url":"https://github.com/sidekiq/sidekiq/blob/main/Changes.md#708"},{"type":"WEB","url":"https://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777"}],"affected":[{"package":{"name":"sidekiq","ecosystem":"RubyGems","purl":"pkg:gem/sidekiq"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.4"},{"fixed":"7.0.8"}]}],"versions":["7.0.4","7.0.5","7.0.6","7.0.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-h3r8-h5qw-4r35/GHSA-h3r8-h5qw-4r35.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"}]}