PT-2022-20463 · Vapor · Vapor

0Xtim

·

Published

2022-06-06

·

Updated

2023-06-29

·

CVE-2022-31019

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Vapor versions prior to 4.61.1
Description The issue is related to unbounded, attacker-controlled stack growth, which can lead to a stack overflow and a process crash when using automatic content decoding. An attacker can craft a request body to make the server crash. The estimated number of potentially affected devices is not specified.
Recommendations For Vapor versions prior to 4.61.1, update to version 4.61.1 to resolve the issue. As a temporary workaround, consider disabling the ContentConfiguration to prevent the use of Form URL Encoded data decoding. Alternatively, restrict the use of the URLEncodedFormDecoder to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Recursion

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-31019
GHSA-QVXG-WJXC-R4GG

Affected Products

Vapor