Name | CVE-2022-23837 |
Description | In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-2943-1, DLA-3360-1 |
Debian Bugs | 1004193 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
ruby-sidekiq (PTS) | jessie | 3.2.6~dfsg-1 | vulnerable |
| stretch (security), stretch (lts), stretch | 4.2.3+dfsg-1+deb9u1 | fixed |
| buster (security), buster, buster (lts) | 5.2.3+dfsg-1+deb10u1 | fixed |
| bullseye | 6.0.4+dfsg-2 | vulnerable |
| bookworm | 6.4.1+dfsg-1 | fixed |
| sid, trixie | 7.3.2+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[bullseye] - ruby-sidekiq <no-dsa> (Minor issue)
https://github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956 (v6.4.0)