CVE-2023-3223 Vulnerability Details

  /     /     /  

CVE-2023-3223 Metadata Quick Info

CVE Published: 27/09/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: redhat | Vendor: Red Hat | Product: Red Hat Fuse 7.12.1
Status : PUBLISHED

CVE-2023-3223 Description

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it\'s possible to bypass the limit by setting the file name in the request to null.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-789
CWE Name: Memory Allocation with Excessive Size Value
Source: Red Hat

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).