CVE-2023-26141

NameCVE-2023-26141
DescriptionVersions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1059300

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ruby-sidekiq (PTS)jessie3.2.6~dfsg-1vulnerable
stretch (security), stretch (lts), stretch4.2.3+dfsg-1+deb9u1vulnerable
buster5.2.3+dfsg-1vulnerable
buster (security)5.2.3+dfsg-1+deb10u1vulnerable
bullseye6.0.4+dfsg-2vulnerable
bookworm6.4.1+dfsg-1vulnerable
trixie, sid6.5.12+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ruby-sidekiqsourcejessie(unfixed)end-of-life
ruby-sidekiqsourcestretch(unfixed)end-of-life
ruby-sidekiqsource(unstable)(unfixed)1059300

Notes

[bookworm] - ruby-sidekiq <no-dsa> (Minor issue)
[bullseye] - ruby-sidekiq <no-dsa> (Minor issue)
[buster] - ruby-sidekiq <no-dsa> (Minor issue, DoS still possible)
https://security.snyk.io/vuln/SNYK-RUBY-SIDEKIQ-5885107
https://github.com/sidekiq/sidekiq/commit/62c90d7c5a7d8a378d79909859d87c2e0702bf89 (v7.1.3)

Search for package or bug name: Reporting problems