Tainted flow: 'url' from os.environ.get (line 52, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
try: if method == "GET": resp = requests.get(url, params=params, headers=headers, timeout=TIMEOUT) else: headers["Content-Type"] = "application/json" resp = requests.post(url, params=params, json=json_body, headers=headers, timeout=TIMEOUT)- Confidence
- 87% confidence
- Finding
- resp = requests.get(url, params=params, headers=headers, timeout=TIMEOUT)
