CVE-2022-24863
Denial of service in http-swagger
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2.6 an attacker may perform a denial of service attack consisting of memory exhaustion on the host system. The cause of the memory exhaustion is down to improper handling of http methods. Users are advised to upgrade. Users unable to upgrade may to restrict the path prefix to the "GET" method as a workaround.
http-swagger es un wrapper de código abierto para generar automáticamente la documentación de la API RESTful con Swagger versión 2.0. En versiones de http-swagger anteriores a 1.2.6 un atacante puede llevar a cabo un ataque de denegación de servicio consistente en el agotamiento de la memoria del sistema anfitrión. La causa del agotamiento de la memoria es debido al manejo inapropiado de los métodos http. Es recomendado a usuarios actualizar. Los usuarios que no puedan actualizar pueden restringir el prefijo de la ruta al método "GET" como medida de mitigación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-04-18 CVE Published
- 2024-08-03 CVE Updated
- 2024-11-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/swaggo/http-swagger/pull/62 | Third Party Advisory | |
https://github.com/swaggo/http-swagger/releases/tag/v1.2.6 | Release Notes | |
https://github.com/swaggo/http-swagger/security/advisories/GHSA-xg75-q3q5-cqmv | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/swaggo/http-swagger/commit/b7d83e8fba85a7a51aa7e45e8244b4173f15049e | 2022-04-27 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Http-swagger Project Search vendor "Http-swagger Project" | Http-swagger Search vendor "Http-swagger Project" for product "Http-swagger" | < 1.2.6 Search vendor "Http-swagger Project" for product "Http-swagger" and version " < 1.2.6" | - |
Affected
|