CVE Vulnerabilities

CVE-2023-3223

Published: Sep 27, 2023 | Modified: May 03, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, its possible to bypass the limit by setting the file name in the request to null.

Affected Software

Name Vendor Start Version End Version
Undertow Redhat * 2.2.24 (excluding)
Red Hat Fuse 7.12.1 RedHat undertow *
Red Hat Fuse 7.13.0 RedHat undertow *
Red Hat JBoss Enterprise Application Platform 7 RedHat undertow *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-undertow-0:2.2.25-3.SP3_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-undertow-0:2.2.25-3.SP3_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-undertow-0:2.2.25-3.SP3_redhat_00001.1.el7eap *
Red Hat Single Sign-On 7.6.5 RedHat undertow *
Red Hat Single Sign-On 7.6 for RHEL 7 RedHat rh-sso7-keycloak-0:18.0.9-1.redhat_00001.1.el7sso *
Red Hat Single Sign-On 7.6 for RHEL 8 RedHat rh-sso7-keycloak-0:18.0.9-1.redhat_00001.1.el8sso *
Red Hat Single Sign-On 7.6 for RHEL 9 RedHat rh-sso7-keycloak-0:18.0.9-1.redhat_00001.1.el9sso *
RHEL-8 based Middleware Containers RedHat rh-sso-7/sso76-openshift-rhel8:7.6-27 *
Undertow Ubuntu bionic *
Undertow Ubuntu trusty *
Undertow Ubuntu xenial *

References