Skip to content

Upgrade Undertow version to 2.3.5 (CVE-2022-4492)#100

Merged
thibaultmeyer merged 1 commit intovoidframework:masterfrom
thibaultmeyer:security/undertow-version-cve-2022-4492-upgrade
Mar 28, 2023
Merged

Upgrade Undertow version to 2.3.5 (CVE-2022-4492)#100
thibaultmeyer merged 1 commit intovoidframework:masterfrom
thibaultmeyer:security/undertow-version-cve-2022-4492-upgrade

Conversation

@thibaultmeyer
Copy link
Contributor

The undertow client is not checking the server identity presented by the server certificate in https connections. This should be performed by default in https and in http/2.

The undertow client is not checking the server identity presented by
the server certificate in https connections. This should be performed
by default in https and in http/2.

Signed-off-by: Thibault Meyer <[email protected]>
@thibaultmeyer thibaultmeyer added the security Correction of vulnerability label Mar 28, 2023
@thibaultmeyer thibaultmeyer added this to the Release 1.7.0 milestone Mar 28, 2023
@thibaultmeyer thibaultmeyer self-assigned this Mar 28, 2023
@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@thibaultmeyer thibaultmeyer merged commit c47fde6 into voidframework:master Mar 28, 2023
@thibaultmeyer thibaultmeyer deleted the security/undertow-version-cve-2022-4492-upgrade branch March 28, 2023 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Correction of vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant