<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 09:16:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-4192</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-4192</link>
      <description>EUVD-2026-4192</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-4192</guid>
    </item>
    <item>
      <title>fkie_cve-2024-25122</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-25122</link>
      <description>&lt;p&gt;sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by any of the following endpoints of sidekiq-unique-jobs&amp;#39; &amp;#34;admin&amp;#34; web UI, allow a super-user attacker, or an unwitting, but authorized, victim, who has received a disguised / crafted link, to successfully execute malicious code, which could potentially steal cookies, session data, or local storage data from the app the sidekiq-unique-jobs web UI is mounted in. 1. `/changelogs`, 2. `/locks` or 3. `/expiring_locks`. This issue has been addressed in versions 7.1.33 and 8.0.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by any of the following endpoints of sidekiq-unique-jobs&amp;#39; &amp;#34;admin&amp;#34; web UI, allow a super-user attacker, or an unwitting, but authorized, victim, who has received a disguised / crafted link, to successfully execute malicious code, which could potentially steal cookies, session data, or local storage data from the app the sidekiq-unique-jobs web UI is mounted in. 1. `/changelogs`, 2. `/locks` or 3. `/expiring_locks`. This issue has been addressed in versions 7.1.33 and 8.0.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-25122</guid>
    </item>
    <item>
      <title>GHSA-cmh9-rx85-xj38 — XSS sidekiq-unique-jobs UI server vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cmh9-rx85-xj38</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: sidekiq-unique-jobs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Cross site scripting (XSS) potentially exposing cookies / sessions / localStorage, fixed by `sidekiq-unique-jobs` v8.0.7.&lt;/p&gt;
&lt;p&gt;Specifically, this is a Reflected (Server-Side), Non-Self, Cross Site Scripting vulnerability, considered a **_P3_** on the BugCrowd [taxonomy](https://bugcrowd.com/vulnerability-rating-taxonomy) with the following categorization:
Cross-Site Scripting (XSS) &amp;gt; Reflected &amp;gt; Non-Self&lt;/p&gt;
&lt;p&gt;It was initially thought there was a second vulnerability (RCE), but it was a false alarm.  Injection is impossible with Redis:&lt;/p&gt;
&lt;p&gt;&amp;gt; String escaping and NoSQL injection
&amp;gt; The Redis protocol has no concept of string escaping, so injection is impossible under normal circumstances using a normal client library. The protocol uses prefixed-length strings and is completely binary safe.&lt;/p&gt;
&lt;p&gt;Ref: https://redis.io/docs/management/security/&lt;/p&gt;
&lt;p&gt;**XSS Vulnerability**&lt;/p&gt;
&lt;p&gt;Specially crafted `GET` request parameters handled by any of the following endpoints of `sidekiq-unique-jobs`&amp;#39; &amp;#34;admin&amp;#34; web UI, allow a super-user attacker, or an unwitting, but authorized, victim, who has received a disguised / crafted link, to successfully execute malicious code, which could potentially steal cookies, session data, or local storage data from the app the `sidekiq-unique-jobs` web UI is mounted in.&lt;/p&gt;
&lt;p&gt;1. `/changelogs`
2. `/locks`
3. `/expiring_locks`&lt;/p&gt;
&lt;p&gt;This means if your `sidekiq-unique-jobs` web UI is mounted at `/sidekiq`, the vulnerable paths are:&lt;/p&gt;
&lt;p&gt;1. `/sidekiq/changelogs`
2. `/sidekiq/locks`
3. `/sideki…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: sidekiq-unique-jobs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Cross site scripting (XSS) potentially exposing cookies / sessions / localStorage, fixed by `sidekiq-unique-jobs` v8.0.7.&lt;/p&gt;
&lt;p&gt;Specifically, this is a Reflected (Server-Side), Non-Self, Cross Site Scripting vulnerability, considered a **_P3_** on the BugCrowd [taxonomy](https://bugcrowd.com/vulnerability-rating-taxonomy) with the following categorization:
Cross-Site Scripting (XSS) &amp;gt; Reflected &amp;gt; Non-Self&lt;/p&gt;
&lt;p&gt;It was initially thought there was a second vulnerability (RCE), but it was a false alarm.  Injection is impossible with Redis:&lt;/p&gt;
&lt;p&gt;&amp;gt; String escaping and NoSQL injection
&amp;gt; The Redis protocol has no concept of string escaping, so injection is impossible under normal circumstances using a normal client library. The protocol uses prefixed-length strings and is completely binary safe.&lt;/p&gt;
&lt;p&gt;Ref: https://redis.io/docs/management/security/&lt;/p&gt;
&lt;p&gt;**XSS Vulnerability**&lt;/p&gt;
&lt;p&gt;Specially crafted `GET` request parameters handled by any of the following endpoints of `sidekiq-unique-jobs`&amp;#39; &amp;#34;admin&amp;#34; web UI, allow a super-user attacker, or an unwitting, but authorized, victim, who has received a disguised / crafted link, to successfully execute malicious code, which could potentially steal cookies, session data, or local storage data from the app the `sidekiq-unique-jobs` web UI is mounted in.&lt;/p&gt;
&lt;p&gt;1. `/changelogs`
2. `/locks`
3. `/expiring_locks`&lt;/p&gt;
&lt;p&gt;This means if your `sidekiq-unique-jobs` web UI is mounted at `/sidekiq`, the vulnerable paths are:&lt;/p&gt;
&lt;p&gt;1. `/sidekiq/changelogs`
2. `/sidekiq/locks`
3. `/sideki…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cmh9-rx85-xj38</guid>
    </item>
    <item>
      <title>gsd-2024-25122</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-25122</link>
      <description>gsd-2024-25122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-25122</guid>
    </item>
  </channel>
</rss>
