QID 996370
Date Published: 2023-12-19
QID 996370: Rubygems (Rubygems) Security Update for resque-scheduler (GHSA-9hmq-fm33-x4xx)
Resque Scheduler version 1.27.4 and above are affected by a cross-site scripting vulnerability. A remote attacker can inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9hmq-fm33-x4xx for updates and patch information.
Vendor References
- GHSA-9hmq-fm33-x4xx -
github.com/advisories/GHSA-9hmq-fm33-x4xx
CVEs related to QID 996370
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9hmq-fm33-x4xx | resque-scheduler |
|