PT-2022-20452 · Vapor · Vapor
0Xtim
+1
·
Published
2022-05-31
·
Updated
2023-06-07
·
CVE-2022-31005
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Vapor versions prior to 4.60.3
Description
Vapor is an HTTP web framework for Swift. Users with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. This issue can be triggered by invalid range headers.
Recommendations
For versions prior to 4.60.3, update to version 4.60.3 to resolve the issue.
As a temporary workaround, consider disabling FileMiddleware and serve assets via a Content Delivery Network.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vapor