PT-2022-27174 · Unknown · Resque Scheduler

·

CVE-2022-44303

·

Published

2022-12-13

·

Updated

2023-12-19

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Resque Scheduler version 1.27.4
Description A remote attacker could inject javascript code to the schedule job or args parameters in "/resque/delayed/jobs/{schedule job}?args={args id}" to execute javascript at the client side, resulting in a Cross-site scripting (XSS) issue.
Recommendations For Resque Scheduler version 1.27.4, update to version 4.10.2 to resolve the issue. As a temporary workaround, consider avoiding clicks on 3rd party or untrusted links to the resque-web interface until the application is patched.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-44303
GHSA-9HMQ-FM33-X4XX
GHSA-Q7JC-V6F2-Q9JR

Affected Products

Resque Scheduler