CVE-2021-21328
Last modified
CVE-2021-21328 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited requests against a vapor instance with different paths. this will create unlimited counters and timers, which will eventually drain the system. 2. downstream services might suffer from this attack as well by being spammed with error paths. This has been patched in 4.40.1. The `DefaultResponder` will rewrite any undefined route paths for to `vapor_route_undefined` to avoid unlimited counters.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vapor Project | Vapor | < 4.40.1 |
References
- https://github.com/vapor/vapor/commit/e3aa712508db2854ac0ab905696c65fd88fa7e23Patch, Third Party Advisory
- https://github.com/vapor/vapor/releases/tag/4.40.1Release Notes, Third Party Advisory
- https://github.com/vapor/vapor/security/advisories/GHSA-gcj9-jj38-hwmcThird Party Advisory
- https://vapor.codes/Product
- https://github.com/vapor/vapor/commit/e3aa712508db2854ac0ab905696c65fd88fa7e23Patch, Third Party Advisory
- https://github.com/vapor/vapor/releases/tag/4.40.1Release Notes, Third Party Advisory
- https://github.com/vapor/vapor/security/advisories/GHSA-gcj9-jj38-hwmcThird Party Advisory
- https://vapor.codes/Product
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21328?
How severe is CVE-2021-21328?
How do I fix CVE-2021-21328?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-21322fastify-http-proxy is an npm package which is a fastify plug…9.8
- CVE-2021-21323Brave is an open source web browser with a focus on privacy …5.3
- CVE-2021-21324GLPI is an open-source asset and IT management software pack…6.5
- CVE-2021-21325GLPI is an open-source asset and IT management software pack…4.8
- CVE-2021-21326GLPI is an open-source asset and IT management software pack…6.5
- CVE-2021-21327GLPI is an open-source asset and IT management software pack…7.5
- CVE-2021-21329RATCF is an open-source framework for hosting Cyber-Security…9.8
- CVE-2021-21330aiohttp is an asynchronous HTTP client/server framework for …6.1
- CVE-2021-21331The Java client for the Datadog API before version 1.0.0-bet…3.3
- CVE-2021-21332Synapse is a Matrix reference homeserver written in python (…8.2
- CVE-2021-21333Synapse is a Matrix reference homeserver written in python (…6.1
- CVE-2021-21334In containerd (an industry-standard container runtime) befor…6.3
Are you affected by CVE-2021-21328?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
