CVE-2022-23837
CVE-2022-23837
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956https://github.com/rubysec/ruby-advisory-db/pull/495https://github.com/TUTUMSPACE/exploits/blob/main/sidekiq.mdhttps://lists.debian.org/debian-lts-announce/2022/03/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2023/03/msg00011.html