github.com
https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md CVE-2022-23837
HIGH
Denial of service in sidekiq
Record summary
CVE-2022-23837 has a selected CVSS score of 7.5 (high).
Description
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
sidekiqBrowse RubyGems / sidekiq | GitHub Advisory | 6.0.0 to < 6.4.0 · Fixed in 6.4.0 | affected |
| Before 5.2.10 · Fixed in 5.2.10 | affected |
References
7github.com
https://github.com/mperham/sidekiq github.com
https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 github.com
https://github.com/rubysec/ruby-advisory-db/pull/495 [debian-lts-announce] 20220310 [SECURITY] [DLA 2943-1] ruby-sidekiq security updatemailing list
https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html [debian-lts-announce] 20230312 [SECURITY] [DLA 3360-1] ruby-sidekiq security updatemailing list
https://lists.debian.org/debian-lts-announce/2023/03/msg00011.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-23837