296,733
Total vulnerabilities in the database
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
| Software | From | Fixed in |
|---|---|---|
| redhat / jboss_enterprise_application_platform | 7.0.0 | 7.0.0.x |
| redhat / single_sign-on | 7.0 | 7.0.x |
| redhat / jboss_fuse | 7.0.0 | 7.0.0.x |
| redhat / undertow | 2.7.0 | 2.7.0.x |
| redhat / migration_toolkit_for_applications | 6.0 | 6.0.x |
io.undertow / undertow-core
|
2.3.0 | 2.3.5.Final |
io.undertow / undertow-core
|
- | 2.2.24.Final |