Логотип exploitDog
bind:CVE-2021-21328
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21328

Количество 2

Количество 2

nvd логотип

CVE-2021-21328

почти 5 лет назад

Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited requests against a vapor instance with different paths. this will create unlimited counters and timers, which will eventually drain the system. 2. downstream services might suffer from this attack as well by being spammed with error paths. This has been patched in 4.40.1. The `DefaultResponder` will rewrite any undefined route paths for to `vapor_route_undefined` to avoid unlimited counters.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-gcj9-jj38-hwmc

больше 2 лет назад

Vapor's Metrics integration could cause a system drain

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-21328

Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited requests against a vapor instance with different paths. this will create unlimited counters and timers, which will eventually drain the system. 2. downstream services might suffer from this attack as well by being spammed with error paths. This has been patched in 4.40.1. The `DefaultResponder` will rewrite any undefined route paths for to `vapor_route_undefined` to avoid unlimited counters.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-gcj9-jj38-hwmc

Vapor's Metrics integration could cause a system drain

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу