HIGH · 7.5

CVE-2023-3223

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service...

Vulnerability Description

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
RedhatUndertow< 2.2.24
RedhatOpenshift Container Platform4.11
RedhatOpenshift Container Platform For Ibm Linuxone4.9
RedhatOpenshift Container Platform For Power4.9
RedhatEnterprise Linux8.0
RedhatJboss Enterprise Application Platform Text-Only Advisories-
RedhatSingle Sign-On-
RedhatJboss Enterprise Application Platform7.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-3223?

CVE-2023-3223 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service...

How severe is CVE-2023-3223?

CVE-2023-3223 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-3223?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Undertow, Redhat Openshift Container Platform, Redhat Openshift Container Platform For Ibm Linuxone, Redhat Openshift Container Platform For Power, Redhat Enterprise Linux.