In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
References
Link | Resource |
---|---|
https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 | Patch Third Party Advisory |
https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md | Exploit Third Party Advisory |
https://github.com/rubysec/ruby-advisory-db/pull/495 | Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/03/msg00011.html |
Information
Published : 2022-01-21 13:15
Updated : 2023-03-12 17:15
NVD link : CVE-2022-23837
Mitre link : CVE-2022-23837
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
debian
- debian_linux
contribsys
- sidekiq