Tainted flow: 'req' from os.environ.get (line 150, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 90% confidence
- Finding
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
- Content
python def _ch(sql, data=None): q = urllib.parse.urlencode({"query": sql, "default_format": "JSONEachRow"}) req = urllib.request.Request(f"{CH_URL}/?{q}", data=data, method="POST" if data else "GET") return urllib.request.urlopen(req, timeout=30).read().decode() def _ch_rows(sql): out = _ch(sql).strip()
