CVE-2024-25122 Information

Description

sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by any of the following endpoints of sidekiq-unique-jobs’ dmin\ web UI allow a super-user attacker or an unwitting but authorized victim who has received a disguised / crafted link to successfully execute malicious code which could potentially steal cookies session data or local storage data from the app the sidekiq-unique-jobs web UI is mounted in. 1. /changelogs 2. /locks or 3. /expiring_locks. This issue has been addressed in versions 7.1.33 and 8.0.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Reference

https://github.com/mhenrixon/sidekiq-unique-jobs/security/advisories/GHSA-cmh9-rx85-xj38 https://github.com/mhenrixon/sidekiq-unique-jobs/commit/ec3afd920c1b55843c72f748a87baac7f8be82ed

Share on: