4.9
CVSSv3

CVE-2023-26141

Published: 14/09/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Versions of the package sidekiq prior to 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

Vulnerable Product Search on Vulmon Subscribe to Product

contribsys sidekiq

Vendor Advisories

Debian Bug report logs - #1059300 ruby-sidekiq: CVE-2023-26141 Package: src:ruby-sidekiq; Maintainer for src:ruby-sidekiq is Debian Ruby Team <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 22 Dec 2023 13:09:06 UTC Severity: grave Tags: security, upst ...
Description<!---->A denial of service vulnerability was found in Sidekiq This flaw allows an attacker to manipulate the localStorage value in the dashboard-chartsjs file and cause excessive polling requestsA denial of service vulnerability was found in Sidekiq This flaw allows an attacker to manipulate the localStorage value in the dashboard-ch ...