Lucene search

K
githubGitHub Advisory DatabaseGHSA-3QC2-V3HP-6CV8
HistorySep 14, 2023 - 6:30 a.m.

sidekiq Denial of Service vulnerability

2023-09-1406:30:19
CWE-345
CWE-400
GitHub Advisory Database
github.com
8
sidekiq
vulnerability
dos
dashboard-charts.js
localstorage
polling requests

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P

EPSS

0.001

Percentile

41.9%

Versions of the package sidekiq before 7.1.3 and 6.5.10 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

Affected configurations

Vulners
Node
sidekiqsidekiqRange<6.5.10
OR
sidekiqsidekiqRange7.0.07.1.3
VendorProductVersionCPE
sidekiqsidekiq*cpe:2.3:a:sidekiq:sidekiq:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P

EPSS

0.001

Percentile

41.9%