ZeroHour

CVE-2022-4492

CVSS 3.1
7.5 high
EPSS
<1%p47
Published
()
Modified
Description

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

Vendors
redhat
Products
build of quarkus, integration camel for spring boot, integration camel k, integration service registry, jboss enterprise application platform, jboss fuse, migration toolkit for applications, migration toolkit for runtimes, single sign-on, undertow
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.