Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43524
HistoryOct 04, 2023 - 6:21 a.m.

Denial Of Service (DOS)

2023-10-0406:21:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
undertow-servlet
denial of service
vulnerability
excessive memory consumption
filesizethreshold
null file name

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.2%

io.undertow: undertow-servlet is vulnerable to Denial Of Service (DOS). The vulnerability is caused by excessive memory consumption due to large multipart content upload handling resulting in OutOfMemoryError while processing @MultipartConfig annotated servlets. This can allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it’s possible to bypass the limit by setting the file name in the request to null.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.2%