Missing or Permissive SSL Hostname Verifier
Overview
Description
Remediation Guidelines
HostnameVerifier hostnameVerifier = org.apache.http.conn.ssl.SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER; HttpsURLConnection.setDefaultHostnameVerifier(hostnameVerifier); // unsafe
References
Configuration
PreviousMissing Optimal Asymmetric Encryption Padding (OAEP)NextMissing Protection against Session Fixation Attacks
Last updated