Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23837

Опубликовано: 21 янв. 2022
Источник: debian

Описание

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-sidekiqfixed6.4.1+dfsg-1package

Примечания

  • https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 (v6.4.0)

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

CVSS3: 7.5
redhat
больше 4 лет назад

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

CVSS3: 7.5
nvd
больше 4 лет назад

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

CVSS3: 7.5
github
больше 4 лет назад

Denial of service in sidekiq