SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21328

Vapor is a web framework for Swift.

MEDIUM 5.3EPSS 1.66%

Does this matter?

Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.

Description

Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited requests against a vapor instance with different paths. this will create unlimited counters and timers, which will eventually drain the system. 2. downstream services might suffer from this attack as well by being spammed with error paths. This has been patched in 4.40.1. The `DefaultResponder` will rewrite any undefined route paths for to `vapor_route_undefined` to avoid unlimited counters.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
1.66% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
vapor project/vapor
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.