Vulnerabilities > CVE-2022-4492 - Unspecified vulnerability in Redhat products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
Vulnerable Configurations
References
- https://access.redhat.com/security/cve/CVE-2022-4492
- https://access.redhat.com/security/cve/CVE-2022-4492
- https://bugzilla.redhat.com/show_bug.cgi?id=2153260
- https://bugzilla.redhat.com/show_bug.cgi?id=2153260
- https://security.netapp.com/advisory/ntap-20230324-0002/
- https://security.netapp.com/advisory/ntap-20230324-0002/