CVE-2023-26141

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*
cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*

History

30 Oct 2023, 17:12

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-14 05:15

Updated : 2024-09-25 19:35


NVD link : CVE-2023-26141

Mitre link : CVE-2023-26141


JSON object : View

Products Affected

contribsys

  • sidekiq
CWE
CWE-345

Insufficient Verification of Data Authenticity