Description
Disabling TLS certificate validation can let an attacker impersonate a remote service with a forged certificate.
Potential impact
- A man-in-the-middle attack may expose credentials, session tokens, or sensitive data.
Remediation
Enable certificate-chain validation and remove test-only verification bypasses from production code.
Examples
Before
c
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0L);
After
c
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 1L);
Explanation:
- Before: Server certificate validation is explicitly disabled.
- After: The default validation is enabled to check the chain of trust.