Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS02NWgyLXdmN20tcTJ2OM4AA2EK

Undertow vulnerable to denial of service

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.

Permalink: https://github.com/advisories/GHSA-65h2-wf7m-q2v8
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02NWgyLXdmN20tcTJ2OM4AA2EK
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 1 year ago
Updated: 7 months ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Percentage: 0.01583
EPSS Percentile: 0.87696

Identifiers: GHSA-65h2-wf7m-q2v8, CVE-2023-3223
References: Blast Radius: 3.6

Affected Packages

maven:io.undertow:undertow-parent
Dependent packages: 0
Dependent repositories: 3
Downloads:
Affected Version Ranges: < 2.2.24.Final
Fixed in: 2.2.24.Final
All affected versions: 2.2.2-0.Final, 2.2.2-1.Final, 2.2.2-2.Final, 2.2.2-3.Final
All unaffected versions: