Loading
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
Use CWE-918, Redhat vendor hub and Build Of Quarkus product page to widen CVE-2022-4492 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2022-4116 and CVE-2023-4853 for nearby disclosures in the same product family.