The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NRed Hat Build Of Quarkus
APPRedhatwszystkie wersjeRed Hat Integration Camel For Spring Boot
APPRedhatwszystkie wersjeRed Hat Integration Camel K
APPRedhatwszystkie wersjeRed Hat Integration Service Registry
APPRedhatwszystkie wersjeRed Hat Jboss Enterprise Application Platform
APPRedhat7.0.0Red Hat Jboss Fuse
APPRedhat7.0.0Red Hat Migration Toolkit For Applications
APPRedhat6.0Red Hat Migration Toolkit For Runtimes
APPRedhatwszystkie wersjeRed Hat Single Sign On
APPRedhat7.0Red Hat Undertow
APPRedhat2.7.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Powiązane podatności
CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)
CVE-2025-12543CRITICAL9.6PL ✓ten sam produkt
Brak walidacji nagłówka Host w serwerze Undertow HTTP
CVE-2022-4361CRITICAL10.0PL ✓ten sam produkt
XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów
CVE-2022-4116CRITICAL9.8PL ✓ten sam produkt
RCE w Quarkus Dev UI Config Editor poprzez drive-by localhost attack
CVE-2019-14887CRITICAL9.1PL ✓ten sam produkt
Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade