Skip to content
COOEY

EXPOSURES › CVE-2022-45597

CVE-2022-45597

CRITICAL
DETAIL
SourceNVD · cve Published2023-03-24 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-45597 ↗
SHAME 35/100

ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion b

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust relationship. This is why self-signed certificates may be used and why validating certificates isn’t as important as doing so for the transport layer certificates."

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.