QID 995284
Date Published: 2023-09-18
QID 995284: Rubygems (Rubygems) Security Update for sidekiq (GHSA-3qc2-v3hp-6cv8)
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3qc2-v3hp-6cv8 for updates and patch information.
Vendor References
- GHSA-3qc2-v3hp-6cv8 -
github.com/advisories/GHSA-3qc2-v3hp-6cv8
CVEs related to QID 995284
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3qc2-v3hp-6cv8 | sidekiq |
|