HIGH7.5
GHSA-jrfj-98qg-qjgv
Denial of service in sidekiq
Quick fix
GHSA-jrfj-98qg-qjgv — sidekiq: upgrade to the fixed version with the command below.
bundle update sidekiqDetails
In `api.rb` in Sidekiq before 6.4.0 and 5.2.10, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-23837[ADVISORY]
- https://github.com/rubysec/ruby-advisory-db/pull/495[WEB]
- https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956[WEB]
- https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md[WEB]
- https://github.com/mperham/sidekiq[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html[WEB]