CVE-2021-30151
Summary
| CVE | CVE-2021-30151 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-06 06:15:00 UTC |
| Updated | 2023-03-13 00:15:00 UTC |
| Description | Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2943-1] ruby-sidekiq security update |
MLIST |
lists.debian.org |
|
| [sidekiq <= v6.2, v5.1.3] Cross-site-scripting (XSS) · Issue #4852 · mperham/sidekiq · GitHub |
MISC |
github.com |
|
| [SECURITY] [DLA 3360-1] ruby-sidekiq security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179123 Debian Security Update for ruby-sidekiq (DLA 2943-1)
- 181627 Debian Security Update for ruby-sidekiq (DLA 3360-1)
- 184856 Debian Security Update for ruby-sidekiq (CVE-2021-30151)
- 240566 Red Hat Update for Satellite 6.11 Release (RHSA-2022:5498)
- 960505 Rocky Linux Security Update for Satellite (RLSA-2022:5498)