5.3 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
0.002 Low
EPSS
Percentile
61.4%
Jetty is a java based web server and servlet engine. In affected versions
servlets with multipart support (e.g. annotated with @MultipartConfig
)
that call HttpServletRequest.getParameter()
or
HttpServletRequest.getParts()
may cause OutOfMemoryError
when the
client sends a multipart request with a part that has a name but no
filename and very large content. This happens even with the default
settings of fileSizeThreshold=0
which should stream the whole part
content to disk. An attacker client may send a large multipart request and
cause the server to throw OutOfMemoryError
. However, the server may be
able to recover after the OutOfMemoryError
and continue its service โ
although it may take some time. This issue has been patched in versions
9.4.51, 10.0.14, and 11.0.14. Users are advised to upgrade. Users unable to
upgrade may set the multipart parameter maxRequestSize
which must be set
to a non-negative value, so the whole multipart content is limited
(although still read into memory).
github.com/eclipse/jetty.project/issues/9076
github.com/eclipse/jetty.project/pull/9344
github.com/eclipse/jetty.project/pull/9345
github.com/eclipse/jetty.project/security/advisories/GHSA-qw69-rqj8-6qw8
github.com/jakartaee/servlet/blob/6.0.0/spec/src/main/asciidoc/servlet-spec-body.adoc#32-file-upload
launchpad.net/bugs/cve/CVE-2023-26048
nvd.nist.gov/vuln/detail/CVE-2023-26048
security-tracker.debian.org/tracker/CVE-2023-26048
www.cve.org/CVERecord?id=CVE-2023-26048