Tainted flow: 'url' from os.environ.get (line 131, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
url = f"{PORTAINER_API_URL}/endpoints/{environment_id}/docker{path}" if method.upper() == "GET": response = requests.get(url, headers=headers, params=payload, timeout=10, verify=False) elif method.upper() == "POST": response = requests.post(url, headers=headers, json=payload, timeout=10, verify=False) elif method.upper() == "DELETE":- Confidence
- 86% confidence
- Finding
- response = requests.get(url, headers=headers, params=payload, timeout=10, verify=False)
