CVE-2022-23837
Denial of service in sidekiq
7.5
HIGH
CVSS 3.1
EPSS 5.3%
Description
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
How to fix CVE-2022-23837
To remediate CVE-2022-23837, upgrade the affected package to a fixed version below.
- Debian/ruby-sidekiq—upgrade to 6.0.4+dfsg-2+deb11u1 or later
- —upgrade to 6.4.0 or later
Is CVE-2022-23837 being exploited?
Moderate — EPSS is 5.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 6.0.4+dfsg-2+deb11u1
- >= 6.0.0, < 6.4.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |