Denial of service in sidekiq
High severity
GitHub Reviewed
Published
Jan 27, 2022
to the GitHub Advisory Database
•
Updated Jan 24, 2023
Package
Affected versions
>= 6.0.0, < 6.4.0
< 5.2.10
Patched versions
6.4.0
5.2.10
Description
Published by the National Vulnerability Database
Jan 21, 2022
Reviewed
Jan 24, 2022
Published to the GitHub Advisory Database
Jan 27, 2022
Last updated
Jan 24, 2023
In
api.rb
in Sidekiq before 6.4.0 and 5.2.10, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.References