CVE-2023-44386
Incorrect request error handling triggers server crash in Vapor
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
Vapor is an HTTP web framework for Swift. There is a denial of service vulnerability impacting all users of affected versions of Vapor. The HTTP1 error handler closed connections when HTTP parse errors occur instead of passing them on. The issue is fixed as of Vapor release 4.84.2.
Vapor es un framework web HTTP para Swift. Existe una vulnerabilidad de denegación de servicio que afecta a todos los usuarios de las versiones afectadas de Vapor. El controlador de errores HTTP1 cerraba las conexiones cuando se producían errores de análisis HTTP en lugar de transmitirlos. El problema se solucionó a partir de la versión 4.84.2 de Vapor.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-09-28 CVE Reserved
- 2023-10-05 CVE Published
- 2024-09-19 CVE Updated
- 2024-11-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-231: Improper Handling of Extra Values
- CWE-617: Reachable Assertion
- CWE-696: Incorrect Behavior Order
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/vapor/vapor/releases/tag/4.84.2 | Release Notes | |
https://github.com/vapor/vapor/security/advisories/GHSA-3mwq-h3g6-ffhm | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/vapor/vapor/commit/090464a654b03148b139a81f8f5ac63b0856f6f3 | 2023-10-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vapor Search vendor "Vapor" | Vapor Search vendor "Vapor" for product "Vapor" | >= 4.83.2 < 4.84.2 Search vendor "Vapor" for product "Vapor" and version " >= 4.83.2 < 4.84.2" | - |
Affected
|