CVE-2021-21328
Description
Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited requests against a vapor instance with different paths. this will create unlimited counters and timers, which will eventually drain the system. 2. downstream services might suffer from this attack as well by being spammed with error paths. This has been patched in 4.40.1. The DefaultResponder will rewrite any undefined route paths for to vapor_route_undefined to avoid unlimited counters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/vapor/vaporSwiftURL | < 4.40.1 | 4.40.1 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/vapor/vapor/commit/e3aa712508db2854ac0ab905696c65fd88fa7e23nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-gcj9-jj38-hwmcghsaADVISORY
- github.com/vapor/vapor/releases/tag/4.40.1nvdRelease NotesThird Party AdvisoryWEB
- github.com/vapor/vapor/security/advisories/GHSA-gcj9-jj38-hwmcnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-21328ghsaADVISORY
- vapor.codesghsaWEB
- vapor.codesnvdProduct
News mentions
0No linked articles in our index yet.