MEDIUM5.7
GHSA-3qc2-v3hp-6cv8
sidekiq Denial of Service vulnerability
Quick fix
GHSA-3qc2-v3hp-6cv8 — sidekiq: upgrade to the fixed version with the command below.
bundle update sidekiqDetails
Versions of the package sidekiq before 7.1.3 and 6.5.10 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-26141[ADVISORY]
- https://github.com/sidekiq/sidekiq/commit/62c90d7c5a7d8a378d79909859d87c2e0702bf89[WEB]
- https://gist.github.com/keeganparr1/1dffd3c017339b7ed5371ed3d81e6b2a[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sidekiq/CVE-2023-26141.yml[WEB]
- https://github.com/sidekiq/sidekiq[PACKAGE]
- https://github.com/sidekiq/sidekiq/blob/6-x/Changes.md#6510[WEB]
- https://github.com/sidekiq/sidekiq/blob/6-x/web/assets/javascripts/dashboard.js#L6[WEB]
- https://github.com/sidekiq/sidekiq/blob/6-x/web/assets/javascripts/dashboard.js%23L6[WEB]
- https://security.snyk.io/vuln/SNYK-RUBY-SIDEKIQ-5885107[WEB]