CVE-2022-4492: SSRF
A flaw was found in undertow. The undertow client is not checking the server identity the server certificate presents in HTTPS connections. This is a compulsory step ( that should at least be performed by default) in HTTPS and in http/2.
Other sources
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
The undertow client is not checking the server identity presented by the server certificate in https connections. This should be performed by default in https and in http/2.
— GitHub
Undertow could provide weaker than expected security, caused by not checking the server identity the server certificate presents in HTTPS connections. An attacker could exploit this vulnerability to launch further attacks on the system
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-4492?
CVE-2022-4492 is a vulnerability in undertow that allows the server identity presented in HTTPS connections to not be checked by the undertow client.
What is the severity of CVE-2022-4492?
The severity of CVE-2022-4492 is high with a severity value of 7.
How does CVE-2022-4492 affect Red Hat EAP7 Undertow?
CVE-2022-4492 affects Red Hat EAP7 Undertow versions 2.2.23-1.SP2_redhat_00001.1.el8ea, 2.2.23-1.SP2_redhat_00001.1.el9ea, and 2.2.23-1.SP2_redhat_00001.1.el7ea.
How does CVE-2022-4492 affect Red Hat EAP7 Undertow Jastow?
CVE-2022-4492 affects Red Hat EAP7 Undertow Jastow versions 2.0.14-1.Final_redhat_00001.1.el8ea, 2.0.14-1.Final_redhat_00001.1.el9ea, and 2.0.14-1.Final_redhat_00001.1.el7ea.
What is the remedy for CVE-2022-4492?
The remedy for CVE-2022-4492 is to upgrade to the specified fixed versions of Red Hat EAP7 Undertow or Red Hat EAP7 Undertow Jastow.