resque is vulnerable to Cross-Site Scripting (XSS)
63
Medium Risk
The resque-web stats page renders the /stats/keys view without escaping the Redis key names it reflects into HTML. A key path segment such as <img src=x onerror=alert(1)> reaches the page and is emitted unescaped, so it executes when an operator opens the crafted /stats/keys/... link. This runs attacker-influenced script in the operator's browser session. The fix escapes the reflected key names before rendering.
You are affected if you are using a version that falls within the vulnerable range and you run the resque-web administrative interface.
resque is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.0.0.
Upgrade the resque library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.