Skip to content

Security: CWE-295 TLS Certificate Validation Bypass — Hardcoded SSL Bypass (NOT MAINTAINED) #38

Description

@LeoWSY-hashblue

Summary

The library hardcodes CURLOPT_SSL_VERIFYPEER => false in its Curl.php constructor, with no option to override it. HTTP Basic/Digest credentials, proxy credentials, and SSL client certificate passphrases are all sent over this unverified TLS connection.

Note: The README states this project is NOT MAINTAINED. Filing for awareness.

Details

Curl.php — constructor:

$curlOptions = array(
    CURLOPT_SSL_VERIFYPEER => false,    // HARDCODED — no override possible
    ...
);
curl_setopt_array($this->ch, $curlOptions);

Credentials sent over unverified TLS:

if (isset($options['login'])) {
    curl_setopt($this->ch, CURLOPT_USERPWD, $options['login'].':'.$options['password']);
}
if (isset($options['proxy_login'])) {
    curl_setopt($this->ch, CURLOPT_PROXYUSERPWD, $options['proxy_login'].':'.$options['proxy_password']);
}
if (isset($options['passphrase'])) {
    curl_setopt($this->ch, CURLOPT_SSLCERTPASSWD, $options['passphrase']);
}

Impact

  • HTTP Basic/Digest credentials transmitted over unverified TLS
  • Proxy credentials and SSL client certificate passphrases exposed
  • Full SOAP request/response payload visible to MITM attacker

Remediation

Remove CURLOPT_SSL_VERIFYPEER => false from the default options array. PHP 5.6+ defaults are secure.

Severity

CVSS 3.1: 8.1 (HIGH) — AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-295: Improper Certificate Validation

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions