
Cloud Vulnerability DB
A community-led vulnerabilities database
A flaw was found in undertow (CVE-2023-3223) affecting servlets annotated with @MultipartConfig. The vulnerability was discovered in versions prior to 2.2.24 and disclosed in May 2023. The issue affects multiple products including Red Hat JBoss Enterprise Application Platform, Red Hat Single Sign-On, and Red Hat Fuse (NVD, Red Hat).
The vulnerability occurs when servlets annotated with @MultipartConfig process large multipart content, which can trigger an OutOfMemoryError. Additionally, if the server uses fileSizeThreshold to limit file sizes, the limit can be bypassed by setting the filename in the request to null. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NetApp Advisory).
Successful exploitation of this vulnerability could allow unauthorized users to cause a remote Denial of Service (DoS) attack by triggering OutOfMemoryError conditions in affected systems. The vulnerability affects the availability of the service while not impacting confidentiality or integrity (Red Hat Bugzilla).
The vulnerability has been fixed in Undertow version 2.2.24. Users are advised to upgrade to this version or later. Multiple vendors have released security updates to address this vulnerability, including Red Hat through various security advisories (RHSA-2023:4505, RHSA-2023:4506, RHSA-2023:4507, and others) (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."