HostnameVerifier should check certificates
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
ID: java-security/hostname-verifier-true
Language: Java
Severity: Error
Category: Security
CWE: 295
Description
A HostnameVerifier
implementation should never just return true
.
Learn More
Non-Compliant Code Examples
public class AllHosts implements HostnameVerifier {
public boolean verify(final String hostname, final SSLSession session) {
return true;
}
}
Compliant Code Examples
public class AllHosts implements HostnameVerifier {
public boolean verify(final String hostname, final SSLSession session) {
if(isValidCertificate) {
return true;
}
return false;
}
}
Seamless integrations. Try Datadog Code Analysis