CVE-2023-30798

Published Apr 21, 2023

Last updated 11 days ago

Overview

Description
There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.
Source
disclosure@vulncheck.com
NVD status
Modified
Products
starlette

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

disclosure@vulncheck.com
CWE-400
nvd@nist.gov
CWE-400

Social media

Hype score
Not currently trending

Configurations