Description
Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. This issue has been patched in version 2.1.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3286 | Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. This issue has been patched in version 2.1.0. |
Github GHSA |
GHSA-r8xx-8vm8-x6wj | Resque vulnerable to Reflected Cross Site Scripting through pathnames |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-27T15:02:43.928Z
Reserved: 2023-12-11T17:53:36.031Z
Link: CVE-2023-50724
Updated: 2024-08-02T22:16:47.310Z
Status : Modified
Published: 2023-12-21T15:15:10.573
Modified: 2024-11-21T08:37:12.957
Link: CVE-2023-50724
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA