Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sidekiq | Contribsys | * | 6.5.10 (excluding) |
Sidekiq | Contribsys | 7.0 (including) | 7.1.3 (excluding) |
Ruby-sidekiq | Ubuntu | bionic | * |
Ruby-sidekiq | Ubuntu | lunar | * |
Ruby-sidekiq | Ubuntu | mantic | * |
Ruby-sidekiq | Ubuntu | trusty | * |
Ruby-sidekiq | Ubuntu | xenial | * |
Red Hat Satellite 6.14 for RHEL 8 | RedHat | rubygem-sidekiq-0:6.5.12-1.el8sat | * |