7.5

CVE-2023-3223

Undertow: outofmemoryerror due to @multipartconfig handling

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Undertow Version < 2.2.24
Redhat ≫ Openshift Container Platform Version 4.11
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.12
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform For Power Version 4.10
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Single Sign-on Version - SwEdition text-only
Redhat ≫ Single Sign-on Version 7.6
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
   Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.4
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
   Redhat ≫ Enterprise Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.68% 0.844
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RedHat 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

https://access.redhat.com/errata/RHSA-2023:4505
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:4506
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:4507
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:4509
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:4918
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:4919
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:4920
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:4921
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:4924
Vendor Advisory
https://access.redhat.com/errata/RHSA-2023:7247
https://access.redhat.com/security/cve/CVE-2023-3223
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2209689
Vendor Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20231027-0004/