GHSA-9hmq-fm33-x4xx

Suggest an improvement
Source
https://github.com/advisories/GHSA-9hmq-fm33-x4xx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-9hmq-fm33-x4xx/GHSA-9hmq-fm33-x4xx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9hmq-fm33-x4xx
Aliases
  • CVE-2022-44303
Published
2023-12-18T19:30:32Z
Modified
2024-02-16T08:14:44.627747Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N CVSS Calculator
Summary
Resque Scheduler Reflected XSS In Delayed Jobs View
Details

Impact

Resque Scheduler version 1.27.4 and above are affected by a cross-site scripting vulnerability. A remote attacker can inject javascript code to the "{schedulejob}" or "args" parameter in /resque/delayed/jobs/{schedulejob}?args={args_id} to execute javascript at client side.

Patches

Fixed in v4.10.2

Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-44303
  • https://github.com/resque/resque-scheduler/issues/761
  • https://github.com/resque/resque/issues/1885
  • https://github.com/resque/resque-scheduler/pull/780
  • https://github.com/resque/resque-scheduler/pull/783
References

Affected packages

RubyGems / resque-scheduler

Package

Name
resque-scheduler
Purl
pkg:gem/resque-scheduler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.27.4
Fixed
4.10.2

Affected versions

2.*

2.0.0.a
2.0.0.b
2.0.0.c
2.0.0.d
2.0.0.e
2.0.0.g
2.0.0.h
2.0.0
2.0.1
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5

3.*

3.0.0
3.1.0

4.*

4.0.0
4.1.0
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
4.9.0
4.10.0
4.10.1