Logo
vuln-group

GHSA-3qc2-v3hp-6cv8

Severity: high (7.5)

First published: Thu Sep 14 2023

Last modified: Tue Sep 26 2023

CWE: 400 345

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

Any of

  • rubygems/sidekiq
    <7.1.3
    fixed in: 7.1.3
SecAlerts Pty Ltd.
Fortitude Valley,
QLD 4006, Australia
© Copyright 2023 - ABN: 70 645 966 203, ACN: 645 966 203