ZeroHour

CVE-2023-3223

CVSS 3.1
7.5 high
EPSS
3%p85
Published
()
Modified
Description

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.

Vendors
redhat
Products
undertow, openshift container platform, openshift container platform for ibm linuxone, openshift container platform for power, jboss enterprise application platform text-only advisories, single sign-on, jboss enterprise application platform
Weakness
CWE-789
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.