CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-45597

Critical · CVSS 9.8

ComponentSpace.Saml2 — Missing SSL Certificate Validation (Improper Certificate Validation)

CVSS
9.8
nvd
EPSS
0.70%
49th pct
KEV
No
Class
other
CWE-295

Description

ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust relationship. This is why self-signed certificates may be used and why validating certificates isn’t as important as doing so for the transport layer certificates."

Search profile — drives PoC discovery

Symbols ComponentSpace.Saml2Saml2SSL certificate validationcertificate validationself-signed certificatestransport layerapplication layertrust relationshipCWE-295
Keywords CVE-2022-45597ComponentSpace.Saml2ComponentSpace SAMLmissing certificate validationSAML certificate validation bypassASP.NET Core SAMLCWE-295SSL validation SAML2componentspace saml2 4.4.0 poc
Versions: 4.4.0

References

Status: enriched · ingested 2026-07-05T18:00:39.000Z · profiled 2026-07-05T18:30:39.000Z