CVE-2023-26141
sidekiq: DoS in dashboard-charts
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
Las versiones del paquete sidekiq anteriores a la 7.1.3 son vulnerables a la Denegación de Servicio (DoS) debido a comprobaciones insuficientes en el archivo dashboard-charts.js. Un atacante puede aprovechar esta vulnerabilidad manipulando el valor de localStorage, lo que provocará peticiones excesivas.
A denial of service vulnerability was found in Sidekiq. This flaw allows an attacker to manipulate the localStorage value in the dashboard-charts.js file and cause excessive polling requests.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-02-20 CVE Reserved
- 2023-09-14 CVE Published
- 2024-09-20 EPSS Updated
- 2024-09-25 CVE Updated
- 2024-09-25 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-345: Insufficient Verification of Data Authenticity
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/sidekiq/sidekiq/blob/6-x/web/assets/javascripts/dashboard.js%23L6 | Broken Link | |
https://security.snyk.io/vuln/SNYK-RUBY-SIDEKIQ-5885107 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://gist.github.com/keeganparr1/1dffd3c017339b7ed5371ed3d81e6b2a | 2024-09-25 |
URL | Date | SRC |
---|---|---|
https://github.com/sidekiq/sidekiq/commit/62c90d7c5a7d8a378d79909859d87c2e0702bf89 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-26141 | 2024-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2239010 | 2024-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Contribsys Search vendor "Contribsys" | Sidekiq Search vendor "Contribsys" for product "Sidekiq" | < 6.5.10 Search vendor "Contribsys" for product "Sidekiq" and version " < 6.5.10" | - |
Affected
| ||||||
Contribsys Search vendor "Contribsys" | Sidekiq Search vendor "Contribsys" for product "Sidekiq" | >= 7.0 < 7.1.3 Search vendor "Contribsys" for product "Sidekiq" and version " >= 7.0 < 7.1.3" | - |
Affected
|