Vapor's Metrics integration could cause a system drain
Package
Affected versions
<= 4.40.0
  Patched versions
4.40.1
  Description
        Published by the National Vulnerability Database
      Feb 26, 2021 
    
  
        Published to the GitHub Advisory Database
      Jun 9, 2023 
    
  
        Reviewed
      Jun 9, 2023 
    
  
        Last updated
      Jun 19, 2023 
    
  
Impact
This is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app with the following attack vector:
Patches
This has been patched in 4.40.1. The
DefaultResponderwill rewrite any undefined route paths for tovapor_route_undefinedto avoid unlimited counters.Workarounds
Don't bootstrap a metrics system or upgrade to 4.40.1
For more information
If you have any questions or comments about this advisory:
References