Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfcc-3g6r-8rg8

Опубликовано: 23 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Undertow client not checking server identity presented by server certificate in https connections

The undertow client is not checking the server identity presented by the server certificate in https connections. This should be performed by default in https and in http/2.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.3.0, < 2.3.5.Final

2.3.5.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.2.24.Final

2.2.24.Final

EPSS

Процентиль: 29%
0.00107
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

CVSS3: 7.5
redhat
около 3 лет назад

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

CVSS3: 7.5
nvd
почти 3 года назад

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

CVSS3: 7.5
debian
почти 3 года назад

The undertow client is not checking the server identity presented by t ...

EPSS

Процентиль: 29%
0.00107
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918