CVE-2023-26141

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*
cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-09-14 05:15

Updated : 2023-11-07 04:09


NVD link : CVE-2023-26141

Mitre link : CVE-2023-26141

CVE.ORG link : CVE-2023-26141


JSON object : View

Products Affected

contribsys

  • sidekiq
CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-400

Uncontrolled Resource Consumption