Description
Sending application traffic to an http:// endpoint allows a network attacker to intercept or modify requests and responses. Calls to external services in production should use HTTPS.
Potential impact
- Exposure or modification of authentication tokens, session identifiers, personal information, and business data.
Remediation
Use https:// URLs for external API and service calls. Apart from explicit local development endpoints such as localhost or loopback addresses, do not leave plaintext HTTP endpoints in production code.
Examples
Before
csharp
await httpClient.GetAsync("http://api.example.com/status");
After
csharp
await httpClient.GetAsync("https://api.example.com/status");
Explanation:
- Before: Plaintext HTTP can expose sensitive application traffic to network attackers.
- After: Use HTTPS for external application traffic and restrict HTTP to explicitly designated local development endpoints.