T09 · Insecure Skill Coding Practices
- Location
scripts/pve_api.py:13- Finding
Proxmox API Credentials Transmitted Without TLS Certificate Verification by Default
- Content
View full analysis
Dict[str, Any]: url = f"{self.base_url}{path}" payload = None headers = {"Authorization": self.auth_header} if data is not None: payload = urllib.parse.urlencode(data).encode() headers["Content-Type"] = "application/x-www-form-urlencoded" req = urllib.request.Request(url, data=payload, headers=headers, method=method.upper()) with urllib.request.urlopen(req, context=self._context(), timeout=30) as resp: return json.loads(resp.read().decode("utf-8")) ``` `scripts/pve_api.py:50-56`: ```python def build_client(verify_ssl: bool = False) -> ProxmoxAPI: return ProxmoxAPI( host=env_or_die("PVE_HOST"), user=env_or_die("PVE_USER"), token_id=env_or_die("PVE_TOKEN_ID"), token_secret=env_or_die("PVE_TOKEN_SECRET"), verify_ssl=verify_ssl, ) ``` `scripts/pve_api.py:64-75`: ```python parser.add_argument("path", help="API path, e.g. /nodes or /cluster/resources") parser.add_argument(" ...[truncated 4081 chars]- Remediation
View remediation
