Improper Certificate Validation The advisory has been revoked - it doesn't affect any version of package componentspace.saml2 Open this link in a new tab
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DOTNET-COMPONENTSPACESAML2-5426100
- published 26 Apr 2024
- disclosed 18 Apr 2023
- credit Patrick van Ek
Introduced: 18 Apr 2023
CVE-2022-45597 Open this link in a new tabHow to fix?
There is no fixed version for ComponentSpace.Saml2
.
Amendment
This was deemed not a vulnerability.
Overview
Affected versions of this package are vulnerable to Improper Certificate Validation due to missing SSL Certificate Validation.
Note:
The vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust relationship. This is why self-signed certificates may be used and why validating certificates isn’t as important as doing so for the transport layer certificates.