CVE-2022-45597
Critical · CVSS 9.8ComponentSpace.Saml2 — Missing SSL Certificate Validation (Improper Certificate Validation)
- CVSS
- 9.8
- nvd
- EPSS
- 0.70%
- 49th pct
- KEV
- No
- Class
- other
- CWE-295
Description
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust relationship. This is why self-signed certificates may be used and why validating certificates isn’t as important as doing so for the transport layer certificates."
Search profile — drives PoC discovery
Symbols ComponentSpace.Saml2Saml2SSL certificate validationcertificate validationself-signed certificatestransport layerapplication layertrust relationshipCWE-295
Keywords CVE-2022-45597ComponentSpace.Saml2ComponentSpace SAMLmissing certificate validationSAML certificate validation bypassASP.NET Core SAMLCWE-295SSL validation SAML2componentspace saml2 4.4.0 poc
Versions: 4.4.0
References
- https://www.componentspace.com/documentation/saml-for-asp-net-core/ComponentSpace%20SAML%20for%20ASP.NET%20Core%20Release%20Notes.pdf
- http://componentspace.com
- http://componentspacesaml2.com
- https://www.componentspace.com/documentation/saml-for-asp-net-core/ComponentSpace%20SAML%20for%20ASP.NET%20Core%20Release%20Notes.pdf
Status: enriched · ingested 2026-07-05T18:00:39.000Z · profiled 2026-07-05T18:30:39.000Z