Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-2271

CVE-2023-3223 Large uploaded file does not persist to disk if the filename is omitted

XMLWordPrintable

    There exists a security vulnerability in Undertow that can cause remote DoS attacks.

    Servlets with multipart support (e.g. annotated with @MultipartConfig) that call HttpServletRequest.getParameter() or HttpServletRequest.getParts() may cause OutOfMemoryError when the client sends a multipart request with a part that has a very large content.

            rhn-engineering-lgao Lin Gao
            rhn-engineering-lgao Lin Gao
            Flavia Rainone
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: