PT-2023-14715 · Componentspace · Componentspace.Saml2

CVE-2022-45597

·

Publicado

2023-03-24

·

Atualizado

2026-07-05

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ComponentSpace.Saml2 version 4.4.0
Description The issue concerns missing SSL certificate validation at the application layer. According to the vendor, this is not considered a vulnerability because certificates are exchanged between trusted entities in a controlled manner, allowing for the use of self-signed certificates. The vendor emphasizes that validating certificates at the application layer is less critical than at the transport layer.
Recommendations For ComponentSpace.Saml2 version 4.4.0, consider implementing additional validation for SSL certificates at the application layer as a precautionary measure, even though the vendor does not consider this a vulnerability. However, since the vendor does not acknowledge this as a vulnerability, there is no official fix or patch provided. As a result, at the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-45597

Produtos afetados

Componentspace.Saml2