High severity7.5NVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026
CVE-2023-3223
CVE-2023-3223
Description
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.undertow:undertow-parentMaven | < 2.2.24.Final | 2.2.24.Final |
Affected products
33- cpe:/a:redhat:integration:1
- Red Hat/Red Hat JBoss Data Grid 7v5cpe:/a:redhat:jboss_data_grid:7
- Red Hat/Red Hat Data Grid 8v5cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7.4+ 4 more
- cpe:/a:redhat:jboss_enterprise_application_platform:7.4
- cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7range: 0:2.2.25-3.SP3_redhat_00001.1.el7eap
- cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8range: 0:2.2.25-3.SP3_redhat_00001.1.el8eap
- cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9range: 0:2.2.25-3.SP3_redhat_00001.1.el9eap
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
- cpe:/a:redhat:jboss_enterprise_bpms_platform:7
- cpe:/a:redhat:jboss_enterprise_brms_platform:7
- Red Hat/Red Hat JBoss Fuse 6v5cpe:/a:redhat:jboss_fuse:6
- Red Hat/Red Hat Fuse 7.12.1v5cpe:/a:redhat:jboss_fuse:7
- cpe:/a:redhat:jbosseapxp
- cpe:/a:redhat:openshift_application_runtimes:1.0
- Red Hat/Red Hat OpenStack Platform 13 (Queens) Operational Toolsv5cpe:/a:redhat:openstack-optools:13
- cpe:/a:redhat:quarkus:2
cpe:/a:redhat:red_hat_single_sign_on:7.6.5+ 5 more
- cpe:/a:redhat:red_hat_single_sign_on:7.6.5
- cpe:/a:redhat:red_hat_single_sign_on:7.6::el7range: 0:18.0.9-1.redhat_00001.1.el7sso
- cpe:/a:redhat:red_hat_single_sign_on:7.6::el8range: 0:18.0.9-1.redhat_00001.1.el8sso
- cpe:/a:redhat:red_hat_single_sign_on:7.6::el9range: 0:18.0.9-1.redhat_00001.1.el9sso
- cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:*
- Red Hat/RHEL-8 based Middleware Containersv5cpe:/a:redhat:rhosemc:1.0::el8Range: 7.6-27
- cpe:/a:redhat:service_registry:2
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_text-only_advisories:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.9:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
16- access.redhat.com/errata/RHSA-2023:4505nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:4506nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:4507nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:4509nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:4918nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:4919nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:4920nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:4921nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:4924nvdVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2023-3223nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-65h2-wf7m-q2v8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-3223ghsaADVISORY
- access.redhat.com/errata/RHSA-2023:7247nvdWEB
- security.netapp.com/advisory/ntap-20231027-0004ghsaWEB
- security.netapp.com/advisory/ntap-20231027-0004/nvd
News mentions
0No linked articles in our index yet.