PT-2023-14715 · Componentspace · Componentspace.Saml2
CVE-2022-45597
·
Publicado
2023-03-24
·
Atualizado
2026-07-05
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ComponentSpace.Saml2 version 4.4.0
Description
The issue concerns missing SSL certificate validation at the application layer. According to the vendor, this is not considered a vulnerability because certificates are exchanged between trusted entities in a controlled manner, allowing for the use of self-signed certificates. The vendor emphasizes that validating certificates at the application layer is less critical than at the transport layer.
Recommendations
For ComponentSpace.Saml2 version 4.4.0, consider implementing additional validation for SSL certificates at the application layer as a precautionary measure, even though the vendor does not consider this a vulnerability. However, since the vendor does not acknowledge this as a vulnerability, there is no official fix or patch provided. As a result, at the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Componentspace.Saml2