CVE-2023-3223
Undertow: outofmemoryerror due to @multipartconfig handling
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
Red Hat · Red Hat build of QuarkusRed Hat · Red Hat Data Grid 8Red Hat · Red Hat Decision Manager 7Red Hat · Red Hat Fuse 7.12.1Red Hat · Red Hat Integration Camel KRed Hat · Red Hat Integration Service RegistryRed Hat · Red Hat JBoss Data Grid 7Red Hat · Red Hat JBoss Enterprise Application Platform 7.1.0Red Hat · Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Red Hat · Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9Red Hat · Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Red Hat · Red Hat JBoss Enterprise Application Platform Expansion PackRed Hat · Red Hat JBoss Fuse 6Red Hat · Red Hat OpenStack Platform 13 (Queens) Operational ToolsRed Hat · Red Hat Process Automation 7Red Hat · Red Hat Single Sign-On 7.6.5Red Hat · Red Hat Single Sign-On 7.6 for RHEL 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 8Red Hat · Red Hat Single Sign-On 7.6 for RHEL 9Red Hat · Red Hat support for Spring BootRed Hat · RHEL-8 based Middleware ContainersQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/errata/RHSA-2023:4505https://access.redhat.com/errata/RHSA-2023:4506https://access.redhat.com/errata/RHSA-2023:4507https://access.redhat.com/errata/RHSA-2023:4509https://access.redhat.com/errata/RHSA-2023:4918https://access.redhat.com/errata/RHSA-2023:4919https://access.redhat.com/errata/RHSA-2023:4920https://access.redhat.com/errata/RHSA-2023:4921https://access.redhat.com/errata/RHSA-2023:4924https://access.redhat.com/errata/RHSA-2023:7247https://access.redhat.com/security/cve/CVE-2023-3223https://bugzilla.redhat.com/show_bug.cgi?id=2209689