Skip to content

OutOfMemoryError for large multipart without filename in Eclipse Jetty

Moderate severity GitHub Reviewed Published Apr 18, 2023 in jetty/jetty.project • Updated Nov 6, 2023

Package

maven org.eclipse.jetty:jetty-server (Maven)

Affected versions

>= 10.0.0, < 10.0.14
>= 11.0.0, < 11.0.14
< 9.4.51.v20230217

Patched versions

10.0.14
11.0.14
9.4.51.v20230217

Description

Impact

Servlets with multipart support (e.g. annotated with @MultipartConfig) that call HttpServletRequest.getParameter() or HttpServletRequest.getParts() may cause OutOfMemoryError when the client sends a multipart request with a part that has a name but no filename and a very large content.

This happens even with the default settings of fileSizeThreshold=0 which should stream the whole part content to disk.

An attacker client may send a large multipart request and cause the server to throw OutOfMemoryError.
However, the server may be able to recover after the OutOfMemoryError and continue its service -- although it may take some time.

A very large number of parts may cause the same problem.

Patches

Patched in Jetty versions

  • 9.4.51.v20230217 - via PR #9345
  • 10.0.14 - via PR #9344
  • 11.0.14 - via PR #9344

Workarounds

Multipart parameter maxRequestSize must be set to a non-negative value, so the whole multipart content is limited (although still read into memory).
Limiting multipart parameter maxFileSize won't be enough because an attacker can send a large number of parts that summed up will cause memory issues.

References

References

@jmcc0nn3ll jmcc0nn3ll published to jetty/jetty.project Apr 18, 2023
Published by the National Vulnerability Database Apr 18, 2023
Published to the GitHub Advisory Database Apr 19, 2023
Reviewed Apr 19, 2023
Last updated Nov 6, 2023

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE ID

CVE-2023-26048

GHSA ID

GHSA-qw69-rqj8-6qw8

Source code

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.