Resque is a Ruby-based background job processing library used extensively in web applications for asynchronous task queuing and worker management. The vendor's vulnerability profile centers on its single product and reflects input-handling risks characteristic of web-facing job processing, with cross-site scripting emerging as the primary observed weakness class. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Resque over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50727MEDIUM Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. Reflected XSS issue occurs when /queues is appended | Dec 22, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-50725MEDIUM Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. The following paths in resque-web have been found to | Dec 22, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-50724MEDIUM Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque ver | Dec 21, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Resque.
Media articles that mention a CVE ID that affects a product developed by Resque — matched by CVE ID, not by vendor name.