CVE-2022-23837 Information
Jun 07, 2022
cve
Description
In api.rb in Sidekiq before 5.2.10 and 6.4.0 there is no limit on the number of days when requesting stats for the graph. This overloads the system affecting the Web UI and makes it unavailable to users.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md https://github.com/rubysec/ruby-advisory-db/pull/495 https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: