Medium severity6.1NVD Advisory· Published Dec 13, 2022· Updated Jul 9, 2026
CVE-2022-44303
CVE-2022-44303
Description
Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
resque-schedulerRubyGems | >= 1.27.4, < 4.10.2 | 4.10.2 |
Affected products
3- cpe:2.3:a:resque-scheduler_project:resque-scheduler:-:*:*:*:*:ruby:*:*
- Resque Scheduler/Resque Schedulerdescription
Patches
Vulnerability mechanics
References
5- trungvm.gitbook.io/cves/resque/resque-1.27.4-multiple-reflected-xss-in-resque-schedule-jobnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-9hmq-fm33-x4xxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-44303ghsaADVISORY
- github.com/resque/resque-scheduler/security/advisories/GHSA-9hmq-fm33-x4xxghsaWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/resque-scheduler/CVE-2022-44303.ymlghsaWEB
News mentions
0No linked articles in our index yet.