ManageIQ / miq_bot

ManageIQ Bot
Apache License 2.0
15 stars 39 forks source link

CVE-2023-26141 (Medium) detected in sidekiq-5.2.10.gem - autoclosed #660

Closed mend-bolt-for-github[bot] closed 7 months ago

mend-bolt-for-github[bot] commented 7 months ago

CVE-2023-26141 - Medium Severity Vulnerability

Vulnerable Library - sidekiq-5.2.10.gem

Simple, efficient background processing for Ruby.

Library home page: https://rubygems.org/gems/sidekiq-5.2.10.gem

Path to dependency file: /Gemfile.lock

Path to vulnerable library: /home/wss-scanner/.gem/ruby/3.2.0/cache/sidekiq-5.2.10.gem

Dependency Hierarchy: - :x: **sidekiq-5.2.10.gem** (Vulnerable Library)

Found in base branch: master

Vulnerability Details

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

Publish Date: 2023-09-14

URL: CVE-2023-26141

CVSS 3 Score Details (4.9)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: High - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://gist.github.com/keeganparr1/1dffd3c017339b7ed5371ed3d81e6b2a

Release Date: 2023-09-14

Fix Resolution: sidekiq - 7.1.3


Step up your Open Source Security Game with Mend here

mend-bolt-for-github[bot] commented 7 months ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.