VDB
Sign up
MEDIUM5.7

GHSA-3qc2-v3hp-6cv8

sidekiq Denial of Service vulnerability

Quick fix

GHSA-3qc2-v3hp-6cv8 — sidekiq: upgrade to the fixed version with the command below.

bundle update sidekiq

Details

Versions of the package sidekiq before 7.1.3 and 6.5.10 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sidekiq
Introduced in: 7.0.0Fixed in: 7.1.3
Fixbundle update sidekiq
RubyGems/sidekiq
Introduced in: 0Fixed in: 6.5.10
Fixbundle update sidekiq

References