CVE-2022-4492
The undertow client is not checking the server identity presented by the server certificate in https connections. This i
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
HIGH · CVSS 7.5
EPSS 0.00155
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0