Lucene search

K
nvd[email protected]NVD:CVE-2022-4492
HistoryFeb 23, 2023 - 8:15 p.m.

CVE-2022-4492

2023-02-2320:15:12
web.nvd.nist.gov
8
undertow
server certificate
https protocol

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

39.4%

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

Affected configurations

Nvd
Node
redhatbuild_of_quarkusMatch-
OR
redhatintegration_camel_for_spring_bootMatch-
OR
redhatintegration_camel_kMatch-
OR
redhatintegration_service_registryMatch-
OR
redhatjboss_enterprise_application_platformMatch7.0.0
OR
redhatjboss_fuseMatch7.0.0
OR
redhatmigration_toolkit_for_applicationsMatch6.0
OR
redhatmigration_toolkit_for_runtimesMatch-
OR
redhatsingle_sign-onMatch7.0
OR
redhatundertowMatch2.7.0
VendorProductVersionCPE
redhatbuild_of_quarkus-cpe:2.3:a:redhat:build_of_quarkus:-:*:*:*:*:*:*:*
redhatintegration_camel_for_spring_boot-cpe:2.3:a:redhat:integration_camel_for_spring_boot:-:*:*:*:*:*:*:*
redhatintegration_camel_k-cpe:2.3:a:redhat:integration_camel_k:-:*:*:*:*:*:*:*
redhatintegration_service_registry-cpe:2.3:a:redhat:integration_service_registry:-:*:*:*:*:*:*:*
redhatjboss_enterprise_application_platform7.0.0cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
redhatjboss_fuse7.0.0cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*
redhatmigration_toolkit_for_applications6.0cpe:2.3:a:redhat:migration_toolkit_for_applications:6.0:*:*:*:*:*:*:*
redhatmigration_toolkit_for_runtimes-cpe:2.3:a:redhat:migration_toolkit_for_runtimes:-:*:*:*:*:*:*:*
redhatsingle_sign-on7.0cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
redhatundertow2.7.0cpe:2.3:a:redhat:undertow:2.7.0:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

39.4%