CVE-2023-50724

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
21/12/2023
Last modified:
02/01/2024

Description

Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. This issue has been patched in version 2.1.0.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:resque:resque:*:*:*:*:*:ruby:*:* 2.1.0 (excluding)