In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md | Exploit Third Party Advisory | 
| https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 | Patch Third Party Advisory | 
| https://github.com/rubysec/ruby-advisory-db/pull/495 | Patch Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html | Mailing List Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2023/03/msg00011.html | |
| https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md | Exploit Third Party Advisory | 
| https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 | Patch Third Party Advisory | 
| https://github.com/rubysec/ruby-advisory-db/pull/495 | Patch Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html | Mailing List Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2023/03/msg00011.html | 
Configurations
                    History
                    21 Nov 2024, 06:49
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md - Exploit, Third Party Advisory | |
| References | () https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 - Patch, Third Party Advisory | |
| References | () https://github.com/rubysec/ruby-advisory-db/pull/495 - Patch, Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html - Mailing List, Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2023/03/msg00011.html - | 
13 Mar 2023, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
25 Apr 2022, 17:22
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | |
| References | (MLIST) https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html - Mailing List, Third Party Advisory | 
10 Mar 2022, 22:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
14 Feb 2022, 14:58
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://github.com/rubysec/ruby-advisory-db/pull/495 - Patch, Third Party Advisory | 
07 Feb 2022, 16:16
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | |
| Summary | In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users. | 
28 Jan 2022, 02:32
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-770 | |
| CVSS | v2 : v3 : | v2 : 5.0 v3 : 7.5 | 
| CPE | cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:* | |
| References | (MISC) https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.md - Exploit, Third Party Advisory | |
| References | (MISC) https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 - Patch, Third Party Advisory | 
21 Jan 2022, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-01-21 21:15
Updated : 2024-11-21 06:49
NVD link : CVE-2022-23837
Mitre link : CVE-2022-23837
CVE.ORG link : CVE-2022-23837
JSON object : View
Products Affected
                debian
- debian_linux
contribsys
- sidekiq
CWE
                
                    
                        
                        CWE-770
                        
            Allocation of Resources Without Limits or Throttling
