Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0759 | The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol. |
Github GHSA |
GHSA-pfcc-3g6r-8rg8 | Undertow client not checking server identity presented by server certificate in https connections |
Wed, 25 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
|
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Wed, 12 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-03-12T14:34:50.123Z
Reserved: 2022-12-14T00:00:00.000Z
Link: CVE-2022-4492
Updated: 2024-08-03T01:41:45.097Z
Status : Modified
Published: 2023-02-23T20:15:12.680
Modified: 2025-03-12T15:15:38.020
Link: CVE-2022-4492
OpenCVE Enrichment
No data.
EUVD
Github GHSA