Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-26141

Опубликовано: 14 сент. 2023
Источник: debian
EPSS Низкий

Описание

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-sidekiqnot-affectedpackage

Примечания

  • https://security.snyk.io/vuln/SNYK-RUBY-SIDEKIQ-5885107

  • https://github.com/sidekiq/sidekiq/commit/62c90d7c5a7d8a378d79909859d87c2e0702bf89 (v7.1.3)

EPSS

Процентиль: 60%
0.004
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVSS3: 4.9
redhat
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVSS3: 7.5
nvd
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVSS3: 5.7
github
больше 2 лет назад

sidekiq Denial of Service vulnerability

EPSS

Процентиль: 60%
0.004
Низкий