CVE-2022-23837: High severity Contribsys Sidekiq vulnerability
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
Other sources
In api.rb in Sidekiq before 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
References:
1. https://security-tracker.debian.org/tracker/CVE-2022-23837 2. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23837 3. https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/sidekiqto a version that resolves this vulnerability.Fixed in 6.4.0 - Upgrade
Upgrade
debian/ruby-sidekiqto a version that resolves this vulnerability.Fixed in 6.0.4+dfsg-2+deb11u1Fixed in 6.4.1+dfsg-1Fixed in 7.3.2+dfsg-1Fixed in 8.1.6+dfsg-1
Event History
Frequently Asked Questions
What is CVE-2022-23837?
CVE-2022-23837 is a vulnerability in Sidekiq before 5.2.10 and 6.4.0 that allows an attacker to overload the system and make the Web UI unavailable.
What is the severity of CVE-2022-23837?
The severity of CVE-2022-23837 is high with a severity value of 7.5.
How does CVE-2022-23837 affect Sidekiq?
CVE-2022-23837 affects Sidekiq by allowing an attacker to overload the system when requesting stats for the graph.
What is the affected software for CVE-2022-23837?
The affected software for CVE-2022-23837 includes Sidekiq versions before 5.2.10 and 6.4.0, as well as certain Debian Linux and Ruby Sidekiq packages.
How can I fix CVE-2022-23837?
To fix CVE-2022-23837, you should update Sidekiq to version 5.2.10 or 6.4.0 depending on your current version.