Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-26141

Опубликовано: 14 сент. 2023
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

A denial of service vulnerability was found in Sidekiq. This flaw allows an attacker to manipulate the localStorage value in the dashboard-charts.js file and cause excessive polling requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-system-containerAffected
Red Hat Satellite 6.14 for RHEL 8rubygem-sidekiqFixedRHSA-2024:079713.02.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400

EPSS

Процентиль: 60%
0.004
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVSS3: 7.5
nvd
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVSS3: 7.5
debian
больше 2 лет назад

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial ...

CVSS3: 5.7
github
больше 2 лет назад

sidekiq Denial of Service vulnerability

EPSS

Процентиль: 60%
0.004
Низкий

4.9 Medium

CVSS3