In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2943-1 | ruby-sidekiq security update |
Debian DLA |
DLA-3360-1 | ruby-sidekiq security update |
EUVD |
EUVD-2022-0634 | In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users. |
Github GHSA |
GHSA-jrfj-98qg-qjgv | Denial of service in sidekiq |
Ubuntu USN |
USN-7695-1 | Sidekiq vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T03:51:45.990Z
Reserved: 2022-01-21T00:00:00
Link: CVE-2022-23837
No data.
Status : Modified
Published: 2022-01-21T21:15:09.283
Modified: 2024-11-21T06:49:20.953
Link: CVE-2022-23837
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN