Contribsys

Sidekiq

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.27%
  • Published 01.03.2024 14:15:53
  • Last modified 18.04.2025 14:30:56

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.

Exploit
  • EPSS 0.27%
  • Published 01.03.2024 14:15:53
  • Last modified 18.04.2025 14:29:50

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.

Exploit
  • EPSS 0.4%
  • Published 14.09.2023 05:15:11
  • Last modified 21.11.2024 07:50:51

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause exce...

Exploit
  • EPSS 78.1%
  • Published 21.04.2023 05:15:07
  • Last modified 21.11.2024 07:40:05

Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.

Exploit
  • EPSS 0.99%
  • Published 21.01.2022 21:15:09
  • Last modified 21.11.2024 06:49:20

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

Exploit
  • EPSS 12.48%
  • Published 06.04.2021 06:15:15
  • Last modified 21.11.2024 06:03:24

Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.