Record summary

CVE-2022-23837 has a selected CVSS score of 7.5 (high).

Description

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory6.0.0 to < 6.4.0 · Fixed in 6.4.0affected
Before 5.2.10 · Fixed in 5.2.10affected

References

7