Loading HuntDB...

GHSA-h3r8-h5qw-4r35

GitHub Security Advisory

sidekiq vulnerable to cross-site scripting

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

sidekiq from 7.0.4 to 7.0.7 is vulnerable to reflected cross-site scripting. A fix was released in version 7.0.8.

Affected Packages

RubyGems sidekiq
Affected versions: 7.0.4 (fixed in 7.0.8)

Related CVEs

Key Information

GHSA ID
GHSA-h3r8-h5qw-4r35
Published
April 21, 2023 6:30 AM
Last Modified
May 1, 2024 1:15 PM
CVSS Score
7.5 /10
Primary Ecosystem
RubyGems
Primary Package
sidekiq
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.