Known Vulnerabilities for products from Contribsys

Listed below are 5 of the newest known vulnerabilities associated with the vendor "Contribsys".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-37279 json Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer... 7.5 - HIGH 2023-09-20 2023-09-25
CVE-2023-26141 json Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dash... 4.9 - MEDIUM 2023-09-14 2023-11-07
CVE-2023-1892 json Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8. 9.6 - CRITICAL 2023-04-21 2023-06-09
CVE-2022-23837 json In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. Th... 7.5 - HIGH 2022-01-21 2023-03-13
CVE-2021-30151 json Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is ... 6.1 - MEDIUM 2021-04-06 2023-03-13