CVE-2022-23837 PUBLISHED CVSS 7.5 HIGH

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

EPSS 0.81% · 74.1th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.81%
74.1th percentile

Affected Products

VendorProductVersions
n/an/an/a
RubyGemssidekiq6.0.0, 0
debiandebian_linux9.0
contribsyssidekiq0, 6.0.0

Timeline

References

Open in Interactive Console →