CVE-2024-25122
Ruby vulnerability analysis and mitigation

Overview

CVE-2024-25122 affects sidekiq-unique-jobs, an open source project that prevents simultaneous Sidekiq jobs with the same unique arguments from running. The vulnerability was discovered and disclosed on February 13, 2024, affecting versions prior to 7.1.33 and 8.0.7. This is a Cross-Site Scripting (XSS) vulnerability in the admin web UI that could potentially expose sensitive data (GitHub Advisory).

Technical details

The vulnerability is classified as a Reflected (Server-Side), Non-Self, Cross-Site Scripting vulnerability. It affects three specific endpoints in the admin web UI: '/changelogs', '/locks', and '/expiring_locks'. The issue stems from unsanitized GET request parameters that allow execution of malicious code. The vulnerability has been assigned a CVSS v3.1 base score of 7.1 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L (GitHub Advisory, NVD).

Impact

The vulnerability could allow attackers to steal cookies, session data, or local storage data from the application where the sidekiq-unique-jobs web UI is mounted. This is particularly critical for implementations that haven't configured the UI on a sandboxed subdomain, making all their sensitive data vulnerable to exposure (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 7.1.33 and 8.0.7. Users are strongly advised to upgrade to these or later versions. Additionally, it is recommended to configure authorization constraints on the admin UI, as it is not protected by any authorization constraint in the default configuration (GitHub Advisory, GitHub Patch).

Additional resources


SourceThis report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68271CRITICAL10
  • RubyRuby
  • openc3
NoYesJan 13, 2026
GHSA-5qw5-wf2q-f538HIGH8.8
  • RubyRuby
  • activerecord-jdbc-adapter
NoYesJan 16, 2026
CVE-2026-22589HIGH7.5
  • RubyRuby
  • spree_core
NoYesJan 10, 2026
CVE-2026-23885MEDIUM6.6
  • RubyRuby
  • alchemy_cms
NoYesJan 19, 2026
GHSA-mpwp-4h2m-765cMEDIUM6.6
  • RubyRuby
  • activejob
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management