In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2943-1 ruby-sidekiq security update
Debian DLA Debian DLA DLA-3360-1 ruby-sidekiq security update
EUVD EUVD EUVD-2022-0634 In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
Github GHSA Github GHSA GHSA-jrfj-98qg-qjgv Denial of service in sidekiq
Ubuntu USN Ubuntu USN USN-7695-1 Sidekiq vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T03:51:45.990Z

Reserved: 2022-01-21T00:00:00

Link: CVE-2022-23837

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-21T21:15:09.283

Modified: 2024-11-21T06:49:20.953

Link: CVE-2022-23837

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-01-22T00:00:00Z

Links: CVE-2022-23837 - Bugzilla

cve-icon OpenCVE Enrichment

No data.