Description
Disabling hostname verification in a TLS connection can let an attacker with a valid certificate for another host impersonate the target server.
Potential impact
- Man-in-the-middle attacks, eavesdropping, or session hijacking may become possible.
Remediation
Enable hostname verification and remove test settings that disable CURLOPT_SSL_VERIFYHOST.
Examples
Before
c
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 0L);
After
c
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L);
Explanation:
- Before: The hostname in the certificate is not checked.
- After: The certificate hostname is checked against the connection target.