跳转到帖子

Red Hat JBossEAP: Memory Allocation with Excessive Size Value (CVE-2023-3223)

recommended_posts

发布于
  • Members

Red Hat JBossEAP: Memory Allocation with Excessive Size Value (CVE-2023-3223)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
08/07/2023
Created
09/20/2024
Added
09/19/2024
Modified
12/20/2024

Description

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.. A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.

Solution(s)

  • red-hat-jboss-eap-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2023-3223
  • CVE - 2023-3223
  • https://access.redhat.com/security/cve/CVE-2023-3223
  • https://bugzilla.redhat.com/show_bug.cgi?id=2209689
  • https://access.redhat.com/errata/RHSA-2023:4505
  • https://access.redhat.com/errata/RHSA-2023:4506
  • https://access.redhat.com/errata/RHSA-2023:4507
  • https://access.redhat.com/errata/RHSA-2023:4509
View more
  • 查看数 700
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…