Disabled certificate validation

Disabled certificate validation

Description

Disabling TLS certificate validation can let an attacker impersonate a remote service with a forged certificate.

Potential impact

  • A man-in-the-middle attack may expose credentials, session tokens, or sensitive data.

Remediation

Enable certificate-chain validation and remove test-only verification bypasses from production code.

Examples

Before

c
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0L);

After

c
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 1L);

Explanation:

  • Before: Server certificate validation is explicitly disabled.
  • After: The default validation is enabled to check the chain of trust.

References