Improper Certificate Validation The advisory has been revoked - it doesn't affect any version of package componentspace.saml2  (opens in a new tab)


Threat Intelligence

EPSS
0.24% (63rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-COMPONENTSPACESAML2-5426100
  • published26 Apr 2024
  • disclosed18 Apr 2023
  • creditPatrick van Ek

Introduced: 18 Apr 2023

CVE-2022-45597  (opens in a new tab)
CWE-295  (opens in a new tab)
First added by Snyk

How to fix?

There is no fixed version for ComponentSpace.Saml2.

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation due to missing SSL Certificate Validation.

Note:

The vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust relationship. This is why self-signed certificates may be used and why validating certificates isn’t as important as doing so for the transport layer certificates.