CVE-2023-3223
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.
- Affected products
- Red Hat Jboss Enterprise Application Platform, Openshift Container Platform, Openshift Container Platform For Ibm Linuxone, Openshift Container Platform For Power, Single Sign-On
- Redhat Undertow
- < 2.2.24
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 2.0% (79th percentile)
- Weakness
- CWE-789
- NVD status
- Modified
- Published
- 2023-09-27
CVE-2023-3223 at NVD
No indexed exploits for CVE-2023-3223 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-3223 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.