diff --git a/Changes.md b/Changes.md index 4205bd98a..34fdca729 100644 --- a/Changes.md +++ b/Changes.md @@ -2,6 +2,12 @@ [Sidekiq Changes](https://github.com/sidekiq/sidekiq/blob/main/Changes.md) | [Sidekiq Pro Changes](https://github.com/sidekiq/sidekiq/blob/main/Pro-Changes.md) | [Sidekiq Enterprise Changes](https://github.com/sidekiq/sidekiq/blob/main/Ent-Changes.md) +7.2.4 +---------- + +- Fix XSS in metrics filtering introduced in 7.2.0, CVE-2024-32887 + Thanks to @UmerAdeemCheema for the security report. + 7.2.3 ---------- diff --git a/lib/sidekiq/version.rb b/lib/sidekiq/version.rb index 1171e582f..e93ed589d 100644 --- a/lib/sidekiq/version.rb +++ b/lib/sidekiq/version.rb @@ -1,6 +1,6 @@ # frozen_string_literal: true module Sidekiq - VERSION = "7.2.3" + VERSION = "7.2.4" MAJOR = 7 end diff --git a/web/views/metrics.erb b/web/views/metrics.erb index c440e67ac..5eefa33ff 100644 --- a/web/views/metrics.erb +++ b/web/views/metrics.erb @@ -12,7 +12,7 @@
<%= csrf_tag %> - +