CVE-2024-21631

MEDIUM EPSS 44.3%
Published Jan 3, 20242y ago · Modified Jun 17, 20262w ago
6.5 CVSS 3.1
Medium
Find Similar
Published Jan 3, 2024 2y ago
Last Modified Jun 17, 2026 2w ago

Description

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI's components, which may cause integer overflows when parsing untrusted inputs. This vulnerability does not affect Vapor directly but could impact applications relying on the URI type for validating user input. The URI type is used in several places in Vapor. A developer may decide to use URI to represent a URL in their application (especially if that URL is then passed to the HTTP Client) and rely on its public properties and methods. However, URI may fail to properly parse a valid (albeit abnormally long) URL, due to string ranges being converted to 16-bit integers. An attacker may use this behavior to trick the application into accepting a URL to an untrusted destination. By padding the port number with zeros, an attacker can cause an integer overflow to occur when the URL authority is parsed and, as a result, spoof the host. Version 4.90.0 contains a patch for this issue. As a workaround, validate user input before parsing as a URI or, if possible, use Foundation's `URL` and `URLComponents` utilities.

CVSS Details

Base Score
6.5
Exploitability
2.8
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity High
Availability None

Threat Intelligence

EPSS Exploit Probability
44.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 3

CWE-1104
CWE-190 Integer Overflow or Wraparound Numeric Error
CWE-20 Improper Input Validation Validation

Affected Products 1

VendorProductVersionRange
vaporvapor* <4.90.0

References 2

  • github.com https://github.com/vapor/vapor/commit/6db3d917b5ce5024a84eb265ef65691383305d70
    Patch
  • github.com https://github.com/vapor/vapor/security/advisories/GHSA-r6r4-5pr8-gjcp
    Vendor Advisory

Remediation

  • github.com https://github.com/vapor/vapor/commit/6db3d917b5ce5024a84eb265ef65691383305d70
    Patch