Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-2271

CVE-2023-3223 Large uploaded file does not persist to disk if the filename is omitted

XMLWordPrintable

    There exists a security vulnerability in Undertow that can cause remote DoS attacks.

    Servlets with multipart support (e.g. annotated with @MultipartConfig) that call HttpServletRequest.getParameter() or HttpServletRequest.getParts() may cause OutOfMemoryError when the client sends a multipart request with a part that has a very large content.

          rhn-engineering-lgao Lin Gao
          rhn-engineering-lgao Lin Gao
          Flavia Rainone
          Votes:
          0 Vote for this issue
          Watchers:
          2 Start watching this issue

            Created:
            Updated:
            Resolved: