T09 · Insecure Skill Coding Practices
- Location
scripts/smartbill_cli.py:59- Finding
SmartBill Credentials Can Be Transmitted to an Arbitrary Configurable Endpoint
- Content
View full analysis
Tuple[Any, Dict[str, str]]: url = f"{self.config.base_url}{path}" if query: compact_query = {k: v for k, v in query.items() if v is not None} if compact_query: url = f"{url}?{urlencode(compact_query)}" payload: Optional[bytes] = None if json_body is not None: payload = json.dumps(json_body).encode("utf-8") for attempt in range(self.config.retries + 1): headers = { "Authorization": self._auth_header, "Accept": accept, } ``` ### Technical Analysis The CLI permits the API destination to be supplied through either `--base-url` or the `SMARTBILL_API_BASE` environment variable. The value is accepted without validating its scheme, hostname, port, or relationship to the legitimate SmartBill service. The client subsequently constructs an HTTP Basic authorization value from the SmartBill username and API token and attaches it to every request sent to the configured destination. Base64 encoding is normal for HTTP Basic authentication and does not protect the ...[truncated 1864 chars]- Remediation
View remediation
