CVE-2022-31005
Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. Version 4.60.3 contains a patch for this issue. As a workaround, disable FileMiddleware and serve via a Content Delivery Network.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- vapor/vapor
- Source
- security-advisories@github.com
References
- https://github.com/vapor/vapor/commit/953a349b539b3e0d3653585c8ffb50c427986df1Patch, Third Party Advisory
- https://github.com/vapor/vapor/releases/tag/4.60.3Release Notes, Third Party Advisory
- https://github.com/vapor/vapor/security/advisories/GHSA-vj2m-9f5j-mpr5Exploit, Third Party Advisory
- https://github.com/vapor/vapor/commit/953a349b539b3e0d3653585c8ffb50c427986df1Patch, Third Party Advisory
- https://github.com/vapor/vapor/releases/tag/4.60.3Release Notes, Third Party Advisory
- https://github.com/vapor/vapor/security/advisories/GHSA-vj2m-9f5j-mpr5Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.