CVE-2022-23837
HIGH7.5EPSS 0.75%Denial of service in sidekiq
發布日:2022/1/27修改日:2026/4/28
描述
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
受影響套件(2)
- Debian/ruby-sidekiqfrom 0, < 6.0.4+dfsg-2+deb11u1
- RubyGems/sidekiq>= 6.0.0, < 6.4.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-23837
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2022-23837
- PATCHhttps://github.com/mperham/sidekiq
- WEBhttps://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956
- WEBhttps://github.com/rubysec/ruby-advisory-db/pull/495
- WEBhttps://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md
- WEBhttps://lists.debian.org/debian-lts-announce/2022/03/msg00015.html