CVE-2022-4492
—CVSS 3.1
7.5 high
EPSS
<1%p47
Published
()
Modified
Description
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
- Vendors
- redhat
- Products
- build of quarkus, integration camel for spring boot, integration camel k, integration service registry, jboss enterprise application platform, jboss fuse, migration toolkit for applications, migration toolkit for runtimes, single sign-on, undertow
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.