Tainted flow: 'BASE_URL' from os.getenv (line 18, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
def check_auth_status(): """Check if session is authenticated.""" try: r = requests.get( f"{BASE_URL}/v1/api/iserver/auth/status", verify=False, timeout=10- Confidence
- 95% confidence
- Finding
- r = requests.get( f"{BASE_URL}/v1/api/iserver/auth/status", verify=False, timeout=10 )
