Cross-site Scripting (XSS) Affecting delayed_job_web package, versions <1.4.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-RUBY-DELAYEDJOBWEB-22005
  • published23 Jan 2018
  • disclosed10 Jan 2018
  • creditZachary Sanchez

Introduced: 10 Jan 2018

CVE-2017-12097  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade delayed_job_web to version 1.4.2 or higher.

Overview

delayed_job_web is a Web interface for delayed_job.

Affected versions of this project are vulnerable to Cross-site Scripting (XSS) attacks via the filter functionality. It allows users to filter output based on the query string of the GET request:

localhost:3000/delayed_job/overview?queues=">+<script>alert(1)<%2Fscript>

An attacker can phish an authenticated user to trigger this vulnerability.

Details

<>

CVSS Scores

version 3.1