A flaw was found in undertow. The undertow client is not checking the server identity the server certificate presents in HTTPS connections. This is a compulsory step ( that should at least be performed by default) in HTTPS and in http/2.
Critical: Apicurio Registry (container images) release and security update [ 2.6.5 GA ]
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Moderate: Service Registry (container images) release and security update [2.5.11 GA]
Important: Service Registry (container images) release and security update [2.5.4 GA]