Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qc2-v3hp-6cv8

Опубликовано: 14 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.7

Описание

sidekiq Denial of Service vulnerability

Versions of the package sidekiq before 7.1.3 and 6.5.10 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

Пакеты

Наименование

sidekiq

rubygems
Затронутые версииВерсия исправления

>= 7.0.0, < 7.1.3

7.1.3

Наименование

sidekiq

rubygems
Затронутые версииВерсия исправления

< 6.5.10

6.5.10

EPSS

Процентиль: 60%
0.004
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-345
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVSS3: 4.9
redhat
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVSS3: 7.5
nvd
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVSS3: 7.5
debian
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial ...

EPSS

Процентиль: 60%
0.004
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-345
CWE-400