The geocoding API request uses an unencrypted HTTP connection rather than HTTPS, which exposes the API key and location data to potential man-in-the-middle attacks. Any data transmitted, including the API key and potentially sensitive location information, could be intercepted by malicious actors monitoring the network traffic.
Likelihood:
High - Man-in-the-middle attacks on unencrypted connections are straightforward to execute.
Impact:
High - Exposing API keys could lead to unauthorized API usage and potential financial implications.
Use HTTPS for all API requests to ensure data is encrypted in transit.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.