PT-2024-5162 · Sidekiq · Sidekiq

Umeradeemcheema

·

Published

2024-04-26

·

Updated

2024-04-29

·

CVE-2024-32887

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Sidekiq versions prior to 7.2.4
Description: The issue is related to a reflected XSS vulnerability in Sidekiq, where the value of the substr parameter is reflected in the response without any encoding, allowing an attacker to inject Javascript code into the response of the application. This could potentially compromise user accounts, force users to perform sensitive actions, steal sensitive data, perform CORS attacks, or deface the web application. If other applications are deployed on the same domain or website as Sidekiq, users of those applications could also be affected, leading to a broader scope of compromise.
Recommendations: To resolve the issue, update to version 7.2.4 or later. As a temporary workaround, consider encoding all output data before rendering it in the response to prevent XSS attacks. Restrict access to the Sidekiq Web UI to minimize the risk of exploitation. Avoid using the substr parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05712
CVE-2024-32887
GHSA-Q655-3PJ8-9FXQ

Affected Products

Sidekiq