First published: Fri Jan 21 2022(Updated: )
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/sidekiq | <6.4.0 | 6.4.0 |
debian/ruby-sidekiq | <=6.0.4+dfsg-2 | 6.4.1+dfsg-1 7.3.2+dfsg-1 |
Sidekiq | <5.2.10 | |
Sidekiq | >=6.0.0<6.4.0 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23837 is a vulnerability in Sidekiq before 5.2.10 and 6.4.0 that allows an attacker to overload the system and make the Web UI unavailable.
The severity of CVE-2022-23837 is high with a severity value of 7.5.
CVE-2022-23837 affects Sidekiq by allowing an attacker to overload the system when requesting stats for the graph.
The affected software for CVE-2022-23837 includes Sidekiq versions before 5.2.10 and 6.4.0, as well as certain Debian Linux and Ruby Sidekiq packages.
To fix CVE-2022-23837, you should update Sidekiq to version 5.2.10 or 6.4.0 depending on your current version.