CVE-2022-4492
published 2023-02-23CVE-2022-4492: The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.60%
44.6th percentile
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.3.8-2 (forky) | undertow 2.3.8-2 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | migration_toolkit_for_applications | — | — |
| redhat | single_sign-on | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.3.8-2 | 2.3.8-2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Undertow) — CVE-2022-4492
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2022-4492 [HIGH] Oracle Oracle Communications Risk Matrix: Install/Upgrade (Undertow) — CVE-2022-4492
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Undertow) vulnerability
CVE: CVE-2022-4492
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Red Hat
undertow: Server identity in https connection is not checked by the undertow client
vendor_redhat·2022-12-14·CVSS 7.5
CVE-2022-4492 [HIGH] CWE-550 undertow: Server identity in https connection is not checked by the undertow client
undertow: Server identity in https connection is not checked by the undertow client
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
A flaw was found in undertow. The undertow client is not checking the server identity the server certificate presents in HTTPS connections. This is a compulsory step ( that should at least be performed by default) in HTTPS and in http/2.
Package: undertow (Red Hat build of Apicurio Registry 2) - Not affected
Package: undertow (Red Hat build of Debezium 1) - Will not fix
Package: undertow (Red Hat build of Quarkus) - Affected
Package: undertow (Red Hat Da
Debian
CVE-2022-4492: undertow - The undertow client is not checking the server identity presented by the server ...
vendor_debian·2022·CVSS 7.5
CVE-2022-4492 [HIGH] CVE-2022-4492: undertow - The undertow client is not checking the server identity presented by the server ...
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
Scope: local
forky: resolved (fixed in 2.3.8-2)
sid: resolved (fixed in 2.3.8-2)
OSV
CVE-2022-4492: The undertow client is not checking the server identity presented by the server certificate in https connections
osv·2023-02-23·CVSS 7.5
CVE-2022-4492 [HIGH] CVE-2022-4492: The undertow client is not checking the server identity presented by the server certificate in https connections
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
OSV
Undertow client not checking server identity presented by server certificate in https connections
osv·2023-02-23
CVE-2022-4492 [CRITICAL] Undertow client not checking server identity presented by server certificate in https connections
Undertow client not checking server identity presented by server certificate in https connections
The undertow client is not checking the server identity presented by the server certificate in https connections. This should be performed by default in https and in http/2.
GHSA
Undertow client not checking server identity presented by server certificate in https connections
ghsa·2023-02-23
CVE-2022-4492 [CRITICAL] CWE-918 Undertow client not checking server identity presented by server certificate in https connections
Undertow client not checking server identity presented by server certificate in https connections
The undertow client is not checking the server identity presented by the server certificate in https connections. This should be performed by default in https and in http/2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-4492https://bugzilla.redhat.com/show_bug.cgi?id=2153260https://security.netapp.com/advisory/ntap-20230324-0002/https://access.redhat.com/security/cve/CVE-2022-4492https://bugzilla.redhat.com/show_bug.cgi?id=2153260https://security.netapp.com/advisory/ntap-20230324-0002/
2023-02-23
Published