Описание
Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. Version 4.60.3 contains a patch for this issue. As a workaround, disable FileMiddleware and serve via a Content Delivery Network.
Ссылки
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.60.3 (исключая)
cpe:2.3:a:vapor:vapor:*:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.0062
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-190
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
Vapor vulnerable to denial of service in HTTP Range Request of FileMiddleware
EPSS
Процентиль: 70%
0.0062
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-190