Improper Certificate Validation The advisory has been revoked - it doesn't affect any version of package componentspace.saml2 Open this link in a new tab


    Threat Intelligence

    EPSS 0.17% (54th percentile)
Expand this section
NVD
9.8 critical

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DOTNET-COMPONENTSPACESAML2-5426100
  • published 26 Apr 2024
  • disclosed 18 Apr 2023
  • credit Patrick van Ek

How to fix?

There is no fixed version for ComponentSpace.Saml2.

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation due to missing SSL Certificate Validation.

Note:

The vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust relationship. This is why self-signed certificates may be used and why validating certificates isn’t as important as doing so for the transport layer certificates.