Resque vulnerable to reflected XSS in resque-web failed and queues lists
Description
        Published to the GitHub Advisory Database
      Dec 18, 2023 
    
  
        Reviewed
      Dec 18, 2023 
    
  
        Published by the National Vulnerability Database
      Dec 22, 2023 
    
  
        Last updated
      Jan 17, 2024 
    
  
Impact
The following paths in resque-web have been found to be vulnerable to reflected XSS:
Patches
v2.2.1
Workarounds
No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.
References
resque/resque#1790
References