Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/mperham/sidekiq/issues/4852 | patch exploit third party advisory issue tracking |
https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2023/03/msg00011.html | mailing list |