GHSA-9hmq-fm33-x4xx

Source
https://github.com/advisories/GHSA-9hmq-fm33-x4xx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-9hmq-fm33-x4xx/GHSA-9hmq-fm33-x4xx.json
Aliases
  • CVE-2022-44303
Published
2023-12-18T19:30:32Z
Modified
2024-02-16T08:14:44.627747Z
Details

Impact

Resque Scheduler version 1.27.4 and above are affected by a cross-site scripting vulnerability. A remote attacker can inject javascript code to the "{schedulejob}" or "args" parameter in /resque/delayed/jobs/{schedulejob}?args={args_id} to execute javascript at client side.

Patches

Fixed in v4.10.2

Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-44303
  • https://github.com/resque/resque-scheduler/issues/761
  • https://github.com/resque/resque/issues/1885
  • https://github.com/resque/resque-scheduler/pull/780
  • https://github.com/resque/resque-scheduler/pull/783
References

Affected packages

RubyGems / resque-scheduler

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.27.4
Fixed
4.10.2

Affected versions

2.*

2.0.0.a
2.0.0.b
2.0.0.c
2.0.0.d
2.0.0.e
2.0.0.g
2.0.0.h
2.0.0
2.0.1
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5

3.*

3.0.0
3.1.0

4.*

4.0.0
4.1.0
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
4.9.0
4.10.0
4.10.1