CVE-2023-3223
Java vulnerability analysis and mitigation

Overview

A flaw was found in undertow (CVE-2023-3223) affecting servlets annotated with @MultipartConfig. The vulnerability was discovered in versions prior to 2.2.24 and disclosed in May 2023. The issue affects multiple products including Red Hat JBoss Enterprise Application Platform, Red Hat Single Sign-On, and Red Hat Fuse (NVD, Red Hat).

Technical details

The vulnerability occurs when servlets annotated with @MultipartConfig process large multipart content, which can trigger an OutOfMemoryError. Additionally, if the server uses fileSizeThreshold to limit file sizes, the limit can be bypassed by setting the filename in the request to null. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NetApp Advisory).

Impact

Successful exploitation of this vulnerability could allow unauthorized users to cause a remote Denial of Service (DoS) attack by triggering OutOfMemoryError conditions in affected systems. The vulnerability affects the availability of the service while not impacting confidentiality or integrity (Red Hat Bugzilla).

Mitigation and workarounds

The vulnerability has been fixed in Undertow version 2.2.24. Users are advised to upgrade to this version or later. Multiple vendors have released security updates to address this vulnerability, including Red Hat through various security advisories (RHSA-2023:4505, RHSA-2023:4506, RHSA-2023:4507, and others) (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-26866HIGH8.8
  • JavaJava
  • org.apache.hugegraph:hg-pd-core
NoYesDec 12, 2025
CVE-2025-54981HIGH7.5
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025
CVE-2025-67721MEDIUM6.3
  • JavaJava
  • trino
NoYesDec 12, 2025
CVE-2025-53960MEDIUM5.9
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025
CVE-2025-54947MEDIUM5.3
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management