A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-09-27T13:54:44.682Z

Updated: 2024-08-02T06:48:07.955Z

Reserved: 2023-06-13T15:50:40.922Z

Link: CVE-2023-3223

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:07.955Z

cve-icon NVD

Status : Modified

Published: 2023-09-27T15:18:56.457

Modified: 2024-11-21T08:16:44.037

Link: CVE-2023-3223

cve-icon Redhat

Severity : Important

Publid Date: 2023-08-07T00:00:00Z

Links: CVE-2023-3223 - Bugzilla