CVE-2023-3223: Undertow: outofmemoryerror due to @multipartconfig handling
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.
Other sources
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause OutOfMemoryError due to huge sized multipart content .This vulnerability can be exploited by unauthorized users to cause remote Denial-of-Service (DoS) attack. And if the server use fileSizeThreshold for the file size limit, it's possible to bypass the limit by setting the file name in the request to null.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3223?
CVE-2023-3223 is a vulnerability found in undertow where servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content, allowing unauthorized users to cause a remote Denial of Service (DoS) attack.
How severe is CVE-2023-3223?
CVE-2023-3223 has a severity rating of high.
Which software is affected by CVE-2023-3223?
The affected software includes undertow versions up to exclusive 2.2.24, Redhat Undertow, Redhat Openshift Container Platform versions 4.11 and 4.12, Redhat Openshift Container Platform For IBM Linuxone versions 4.9 and 4.10, Redhat Openshift Container Platform For Power versions 4.9 and 4.10, Redhat Single Sign-on version 7.6, Redhat Jboss Enterprise Application Platform version 7.4.
How do I fix CVE-2023-3223?
To fix CVE-2023-3223, update undertow to version 2.2.24 or undertow-parent to version 2.2.24.Final depending on the software used. For Redhat products, refer to the respective security advisories provided in the references section for more information on the fix.
Where can I find more information about CVE-2023-3223?
You can find more information about CVE-2023-3223 in the Red Hat Security Advisories: RHSA-2023:4509, RHSA-2023:4505, and RHSA-2023:4506.