The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
2023-02-23T20:15:12.680
2025-03-12T15:15:38.020
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | build_of_quarkus | - | Yes |
Application | redhat | integration_camel_for_spring_boot | - | Yes |
Application | redhat | integration_camel_k | - | Yes |
Application | redhat | integration_service_registry | - | Yes |
Application | redhat | jboss_enterprise_application_platform | 7.0.0 | Yes |
Application | redhat | jboss_fuse | 7.0.0 | Yes |
Application | redhat | migration_toolkit_for_applications | 6.0 | Yes |
Application | redhat | migration_toolkit_for_runtimes | - | Yes |
Application | redhat | single_sign-on | 7.0 | Yes |
Application | redhat | undertow | 2.7.0 | Yes |