{
  "threat_severity" : "Moderate",
  "public_date" : "2022-01-22T00:00:00Z",
  "bugzilla" : {
    "description" : "sidekiq: WebUI Denial of Service caused by number of days on graph",
    "id" : "2044581",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2044581"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-770",
  "details" : [ "In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.", "A denial of service vulnerability was found in job scheduler sidekiq. An attacker can request statistics for the graph and, since there were no limits on the days parameter, overload the system, affecting the WebUI." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Satellite 6.11 for RHEL 7",
    "release_date" : "2022-07-05T00:00:00Z",
    "advisory" : "RHSA-2022:5498",
    "cpe" : "cpe:/a:redhat:satellite:6.11::el7",
    "package" : "tfm-rubygem-sidekiq-0:5.2.10-1.el7sat"
  }, {
    "product_name" : "Red Hat Satellite 6.11 for RHEL 8",
    "release_date" : "2022-07-05T00:00:00Z",
    "advisory" : "RHSA-2022:5498",
    "cpe" : "cpe:/a:redhat:satellite:6.11::el8",
    "package" : "tfm-rubygem-sidekiq-0:5.2.10-1.el8sat"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat 3scale API Management Platform 2",
    "fix_state" : "Will not fix",
    "package_name" : "rubygem-sidekiq",
    "cpe" : "cpe:/a:redhat:red_hat_3scale_amp:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-23837\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-23837\nhttps://github.com/advisories/GHSA-jrfj-98qg-qjgv" ],
  "name" : "CVE-2022-23837",
  "csaw" : false
}