Record summary

CVE-2023-1892 has a selected CVSS score of 9.6 (critical); EIP currently links 1 Nuclei template.

Description

Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List7.0.4affected
Before 7.0.8affected
GitHub Advisory7.0.4 to < 7.0.8 · Fixed in 7.0.8affected

Nuclei templates

1
ProjectDiscoveryCRITICALSidekiq < 7.0.8 - Cross-Site ScriptingCVSS 9.6

An XSS vulnerability on a Sidekiq admin panel can pose serious risks to the security and functionality of the system.

Impact

Unauthenticated attackers can inject malicious JavaScript through the period parameter in Sidekiq metrics endpoints, potentially stealing administrator session cookies and accessing sensitive job queue information and worker statistics.

Remediation

Update Sidekiq to version 7.0.8 or later that properly sanitizes the period parameter and encodes output in the metrics dashboard.

WeaknessesCWE-79
Authorsritikchaddha, princechaddha
Template tagscvecve2023sidekiqcontribsysxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CPE: cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*
Shodan: http.title:"sidekiq"
FOFA: title="Sidekiq"
FOFA: title="sidekiq"
Google: intitle:"sidekiq"

Source: ProjectDiscovery

References

6