Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-4492

Опубликовано: 14 дек. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

A flaw was found in undertow. The undertow client is not checking the server identity the server certificate presents in HTTPS connections. This is a compulsory step ( that should at least be performed by default) in HTTPS and in http/2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apicurio Registry 2undertowNot affected
Red Hat build of Debezium 1undertowWill not fix
Red Hat build of QuarkusundertowAffected
Red Hat Data Grid 8undertowWill not fix
Red Hat Decision Manager 7undertowOut of support scope
Red Hat Integration Camel K 1undertowAffected
Red Hat Integration Camel Quarkus 1undertowWill not fix
Red Hat JBoss Data Grid 7undertowOut of support scope
Red Hat JBoss Enterprise Application Platform 6undertowOut of support scope
Red Hat JBoss Fuse 6undertowOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-550
https://bugzilla.redhat.com/show_bug.cgi?id=2153260undertow: Server identity in https connection is not checked by the undertow client

EPSS

Процентиль: 29%
0.00107
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

CVSS3: 7.5
nvd
почти 3 года назад

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

CVSS3: 7.5
debian
почти 3 года назад

The undertow client is not checking the server identity presented by t ...

CVSS3: 9.8
github
почти 3 года назад

Undertow client not checking server identity presented by server certificate in https connections

EPSS

Процентиль: 29%
0.00107
Низкий

7.5 High

CVSS3

Уязвимость CVE-2022-4492