Property
Languagepython
Severitylow
CWECWE-319: Cleartext Transmission of Sensitive Information
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The code creates a urllib.request.Request to an ‘ftp://’ URL, which uses an unencrypted FTP connection. This means any data sent or received can be intercepted or modified by attackers on the network.

Impact#

Transmitting sensitive data over unencrypted FTP exposes it to eavesdropping and tampering, potentially leading to credential theft, data leaks, or unauthorized access. Attackers could read or alter transferred information, putting both user data and system integrity at risk.