High severity7.5NVD Advisory· Published Jan 21, 2022· Updated Jun 17, 2026
CVE-2022-23837
CVE-2022-23837
Description
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sidekiqRubyGems | >= 6.0.0, < 6.4.0 | 6.4.0 |
sidekiqRubyGems | < 5.2.10 | 5.2.10 |
Affected products
4Patches
Vulnerability mechanics
References
7- github.com/mperham/sidekiq/commit/7785ac1399f1b28992adb56055f6acd88fd1d956nvdPatchThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/pull/495nvdPatchThird Party AdvisoryWEB
- github.com/TUTUMSPACE/exploits/blob/main/sidekiq.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jrfj-98qg-qjgvghsaADVISORY
- lists.debian.org/debian-lts-announce/2022/03/msg00015.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-23837ghsaADVISORY
- lists.debian.org/debian-lts-announce/2023/03/msg00011.htmlnvd
News mentions
0No linked articles in our index yet.