Description
urllib not only opens http:// or https:// URLs, but also ftp:// and file://. With this, it might be possible to open local files on the executing machine which might be a security risk if the URL to open can be manipulated by an external user.
Occurrences
There is 1 occurrence of this issue in the repository.
See all occurrences on DeepSource → app.deepsource.com/gh/john-bampton/john-bampton.github.io/issue/BAN-B310/occurrences/
Description
urllibnot only openshttp://orhttps://URLs, but alsoftp://andfile://. With this, it might be possible to open local files on the executing machine which might be a security risk if the URL to open can be manipulated by an external user.Occurrences
There is 1 occurrence of this issue in the repository.
See all occurrences on DeepSource → app.deepsource.com/gh/john-bampton/john-bampton.github.io/issue/BAN-B310/occurrences/