The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NRed Hat Build Of Quarkus
APPRedhatall versionsRed Hat Integration Camel For Spring Boot
APPRedhatall versionsRed Hat Integration Camel K
APPRedhatall versionsRed Hat Integration Service Registry
APPRedhatall versionsRed Hat Jboss Enterprise Application Platform
APPRedhat7.0.0Red Hat Jboss Fuse
APPRedhat7.0.0Red Hat Migration Toolkit For Applications
APPRedhat6.0Red Hat Migration Toolkit For Runtimes
APPRedhatall versionsRed Hat Single Sign On
APPRedhat7.0Red Hat Undertow
APPRedhat2.7.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product
RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)
CVE-2025-12543CRITICAL9.6PL ✓same product
Brak walidacji nagłówka Host w serwerze Undertow HTTP
CVE-2022-4361CRITICAL10.0PL ✓same product
XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów
CVE-2022-4116CRITICAL9.8PL ✓same product
RCE w Quarkus Dev UI Config Editor poprzez drive-by localhost attack
CVE-2019-14887CRITICAL9.1PL ✓same product
Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade