Skip to content

Reflected XSS in Queue Endpoint

Moderate
PatrickTulskie published GHSA-r9mq-m72x-257g Dec 18, 2023

Package

bundler resque (RubyGems)

Affected versions

< 2.6.0

Patched versions

2.6.0

Description

Impact

Reflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web.

Patches

v2.6.0

Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

References

#1865

Severity

Moderate
6.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N

CVE ID

CVE-2023-50727

Weaknesses

Credits