CVE-2021-21328
Vapor is a web framework for Swift.
Does this matter?
Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.
Description
Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited requests against a vapor instance with different paths. this will create unlimited counters and timers, which will eventually drain the system. 2. downstream services might suffer from this attack as well by being spammed with error paths. This has been patched in 4.40.1. The `DefaultResponder` will rewrite any undefined route paths for to `vapor_route_undefined` to avoid unlimited counters.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- vapor project/vapor
- Source
- security-advisories@github.com
References
- https://github.com/vapor/vapor/commit/e3aa712508db2854ac0ab905696c65fd88fa7e23Patch, Third Party Advisory
- https://github.com/vapor/vapor/releases/tag/4.40.1Release Notes, Third Party Advisory
- https://github.com/vapor/vapor/security/advisories/GHSA-gcj9-jj38-hwmcThird Party Advisory
- https://vapor.codes/Product
- https://github.com/vapor/vapor/commit/e3aa712508db2854ac0ab905696c65fd88fa7e23Patch, Third Party Advisory
- https://github.com/vapor/vapor/releases/tag/4.40.1Release Notes, Third Party Advisory
- https://github.com/vapor/vapor/security/advisories/GHSA-gcj9-jj38-hwmcThird Party Advisory
- https://vapor.codes/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.