Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| sidekiq(RubyGems) | 0 | 5.2.0 | N/A |
| sidekiq(RubyGems) | 6.0.0 | 6.2.1 | N/A |
CVSS Metrics