Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23837

Опубликовано: 21 янв. 2022
Источник: debian

Описание

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-sidekiqfixed6.4.1+dfsg-1package

Примечания

  • https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 (v6.4.0)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

CVSS3: 7.5
redhat
около 4 лет назад

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

CVSS3: 7.5
nvd
около 4 лет назад

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

CVSS3: 7.5
github
около 4 лет назад

Denial of service in sidekiq