Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-3223
HistorySep 27, 2023 - 3:18 p.m.

Design/Logic Flaw

2023-09-2715:18:00
PRIOn knowledge base
www.prio-n.com
13
logic flaw
undertow
multipartconfig
outofmemoryerror
denial of service
file size
bypass

7.2 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.2%

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it’s possible to bypass the limit by setting the file name in the request to null.

7.2 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.2%