• Home
  • CodeSent for Apigee
    • Features
    • Rules
    • API
  • Demo
  • Pricing
  • Blog
  • Courses
  • Contacts
  • Sign in
  • Get a demo
    • Home
    • CodeSent for Apigee
      • Features
      • Rules
      • API
    • Demo
    • Pricing
    • Blog
    • Courses
    • Contacts
  • Sign in
  • Get a demo
  1. Rules
  • Group by:
  • None
    None Severity
  • Filter by:
  • Severity
    Info Low Medium High Critical
  • Tags
    Authentication & Authorisation Code Quality Data Validation Data at Rest Data in Transit DoS Protection Error Handling Secure Configuration
  • Scopes
    ServiceCallout MessageLogging Step RouteRule Flow Target AccessControl AssignMessage BasicAuthentication Condition FlowCallout HMAC JavaScript JSONThreatProtection OAuthV2 PreFlow Proxy Quota Response SpikeArrest VerifyAPIKey XMLThreatProtection
Name Severity Scopes Tags Links
Flow accepts requests with any method Medium Flow Data Validation CWE-749
Flow accepts confidential data as URL parameters High Flow PreFlow Data in Transit CWE-598
Error flow variable is set but not checked in request phase Medium Step Error Handling CWE-390
Connection to the system is not encrypted Critical ServiceCallout MessageLogging Target Data in Transit CWE-319
Confidential data is used as a cache key High Step Data at Rest CWE-256 CWE-312
Condition has undefined variables Medium Step RouteRule Flow Code Quality CWE-570 CWE-571
Cache lookup variable is overwritten Low Step Code Quality CWE-472
Cache is accessed without prior authentication High Step Authentication & Authorisation CWE-306
Bypassing AccessControl policy via True-Client-IP header Critical AccessControl Data Validation CWE-290
Authorization header is not removed before the request is sent to target system High Proxy Data in Transit CWE-201
AssignMessage request parameters pollution High AssignMessage Data Validation CWE-20
AccessControl allows all IPs Medium AccessControl Data Validation CWE-290
API Key is not removed before the request is sent to target system High Proxy Data in Transit CWE-201
  • 1
  • 2
  • 3

Sentinel Strength for Secure API Gateway Code

  • ​Home
  • Features
  • Demo
  • Rules
  • Blog
  • Apigee Best Security Practices
  • Contact us

  • ​+381 637 736 053 ​
  • ​info@codesent.io
Socials
​
Copyright © CodeSent
Apigee is a registered trademark of Google LLC

We use cookies to provide you a better user experience on this website. Cookie Policy

Only essentials I agree