undertow: Server identity in https connection is not checked by the undertow client
Published Feb 23, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.60%
Description
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
Affected products
- Vendor n/a Product Undertow Defaultn/a
- Version 2.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Undertow | n/a |
|
- n/a
- n/a
- n/a
- n/a
- 7.0.0
- 7.0.0
- 6.0
- n/a
- 7.0
- 2.7.0
No data.
MTA-6.2-RHEL-9
mta/mta-operator-bundle:6.2.0-29
Fixed · RHSA-2023:4627
Migration Toolkit for Runtimes 1 on RHEL 8
mtr/mtr-web-container-rhel8:1.1-8
Fixed · RHSA-2023:3813
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-22
Fixed · RHSA-2023:2710
RHINT Camel-Springboot 3.20.1
undertow
Fixed · RHSA-2023:2100
RHPAM 7.13.4 async
n/a
Fixed · RHSA-2023:4983
Red Hat Fuse 7.12
undertow
Fixed · RHSA-2023:3954
Red Hat JBoss Enterprise Application Platform 7
undertow
Fixed · RHSA-2023:1516
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-glassfish-el-0:3.0.1-4.b08_redhat_00005.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-hibernate-0:5.1.17-3.Final_redhat_00004.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jackson-databind-0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jboss-ejb-client-0:4.0.12-1.Final_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-netty-0:4.1.63-2.Final_redhat_00003.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-undertow-0:1.4.18-16.SP14_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-0:7.1.11-4.GA_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-elytron-0:1.1.14-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-naming-client-0:1.0.13-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-openssl-0:1.0.12-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-openssl-linux-0:1.0.12-6.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el8eap
Fixed · RHSA-2023:1513
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2023:1513
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el9eap
Fixed · RHSA-2023:1514
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2023:1514
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el7eap
Fixed · RHSA-2023:1512
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2023:1512
Red Hat Single Sign-On 7
undertow
Fixed · RHSA-2023:2713
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el7sso
Fixed · RHSA-2023:2705
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el8sso
Fixed · RHSA-2023:2706
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el9sso
Fixed · RHSA-2023:2707
Red Hat Data Grid 8
undertow
Will not fix
Red Hat Decision Manager 7
undertow
Out of support scope
Red Hat Integration Camel K 1
undertow
Affected
Red Hat Integration Camel Quarkus 1
undertow
Will not fix
Red Hat JBoss Data Grid 7
undertow
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
undertow
Out of support scope
Red Hat JBoss Fuse 6
undertow
Out of support scope
Red Hat JBoss Fuse Service Works 6
undertow
Not affected
Red Hat Process Automation 7
undertow
Out of support scope
Red Hat build of Apicurio Registry 2
undertow
Not affected
Red Hat build of Debezium 1
undertow
Will not fix
Red Hat build of Quarkus
undertow
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| MTA-6.2-RHEL-9 | mta/mta-operator-bundle:6.2.0-29 | Fixed | RHSA-2023:4627 |
| Migration Toolkit for Runtimes 1 on RHEL 8 | mtr/mtr-web-container-rhel8:1.1-8 | Fixed | RHSA-2023:3813 |
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-22 | Fixed | RHSA-2023:2710 |
| RHINT Camel-Springboot 3.20.1 | undertow | Fixed | RHSA-2023:2100 |
| RHPAM 7.13.4 async | n/a | Fixed | RHSA-2023:4983 |
| Red Hat Fuse 7.12 | undertow | Fixed | RHSA-2023:3954 |
| Red Hat JBoss Enterprise Application Platform 7 | undertow | Fixed | RHSA-2023:1516 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-glassfish-el-0:3.0.1-4.b08_redhat_00005.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-hibernate-0:5.1.17-3.Final_redhat_00004.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jackson-databind-0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jboss-ejb-client-0:4.0.12-1.Final_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-netty-0:4.1.63-2.Final_redhat_00003.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-undertow-0:1.4.18-16.SP14_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-0:7.1.11-4.GA_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-elytron-0:1.1.14-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-naming-client-0:1.0.13-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-openssl-0:1.0.12-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-openssl-linux-0:1.0.12-6.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el8eap | Fixed | RHSA-2023:1513 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2023:1513 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el9eap | Fixed | RHSA-2023:1514 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2023:1514 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el7eap | Fixed | RHSA-2023:1512 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2023:1512 |
| Red Hat Single Sign-On 7 | undertow | Fixed | RHSA-2023:2713 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el7sso | Fixed | RHSA-2023:2705 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el8sso | Fixed | RHSA-2023:2706 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el9sso | Fixed | RHSA-2023:2707 |
| Red Hat Data Grid 8 | undertow | Will not fix | n/a |
| Red Hat Decision Manager 7 | undertow | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | undertow | Affected | n/a |
| Red Hat Integration Camel Quarkus 1 | undertow | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | undertow | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | undertow | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | undertow | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | undertow | Not affected | n/a |
| Red Hat Process Automation 7 | undertow | Out of support scope | n/a |
| Red Hat build of Apicurio Registry 2 | undertow | Not affected | n/a |
| Red Hat build of Debezium 1 | undertow | Will not fix | n/a |
| Red Hat build of Quarkus | undertow | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Mar 12, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.60% (0.00596) | 46.55th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.60% (0.00596) | 43.65th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.12% (0.00121) | 28.56th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.09% (0.00091) | 40.42th | v3 (v2023.03.01) |
| Mar 27, 2024 | 0.08% (0.00081) | 33.16th | v3 (v2023.03.01) |
| Mar 1, 2024 | 0.07% (0.00075) | 30.27th | v3 (v2023.03.01) |
| Mar 25, 2023 | 0.05% (0.00054) | 19.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00048) | 14.90th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 24, 2023 | 0.89% (0.00885) | 27.85th | v2 (v2022.01.01) |
References (13)
- https://access.redhat.com/security/cve/CVE-2022-4492 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2153260 Issue TrackingVendor Advisory
- https://github.com/advisories/GHSA-pfcc-3g6r-8rg8 Advisory
- https://github.com/undertow-io/undertow/blob/master/core/src/main/java/io/undertow/security/impl/ClientCertAuthenticationMechanism.java
- https://github.com/undertow-io/undertow/pull/1447
- https://github.com/undertow-io/undertow/pull/1447/commits/e5071e52b72529a14d3ec436ae7102cea5d918c4
- https://github.com/undertow-io/undertow/pull/1457
- https://github.com/undertow-io/undertow/pull/1457/commits/a4d3b167126a803cc4f7fb740dd9a6ecabf59342
- https://issues.redhat.com/browse/MTA-93
- https://issues.redhat.com/browse/UNDERTOW-2212
- https://nvd.nist.gov/vuln/detail/CVE-2022-4492
- https://security.netapp.com/advisory/ntap-20230324-0002
- https://www.cve.org/CVERecord?id=CVE-2022-4492
Change history (0)
No recorded changes yet.