VYPR
Medium severity6.1NVD Advisory· Published Dec 13, 2022· Updated Jul 9, 2026

CVE-2022-44303

CVE-2022-44303

Description

Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
resque-schedulerRubyGems
>= 1.27.4, < 4.10.24.10.2

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.