Flow BasicAuthentication JavaScript Proxy
Name Scopes Tags Links
High
API Key is not removed before the request is sent to target system Proxy Data in Transit CWE-201
Authorization header is not removed before the request is sent to target system Proxy Data in Transit CWE-201
Flow accepts confidential data as URL parameters Flow PreFlow Data in Transit CWE-598
JSONThreatProtection policy is not applied to a request body with JSON type Flow Data Validation CWE-502 CWE-20
Proxy doesn't have default flow Proxy Code Quality Data Validation CWE-20
Use of weak hash algorithms AssignMessage HMAC JavaScript Secure Configuration CWE-327
Medium
Condition has undefined variables Step RouteRule Flow Code Quality CWE-570 CWE-571
Flow accepts requests with any method Flow Data Validation CWE-749
Flow doesn't limit HTTP methods correctly Flow Data Validation CWE-749
Lack of DefaultFaultRule Target Proxy Error Handling CWE-390
MatchesPath is applied to a static parameter Target Proxy Code Quality Data Validation CWE-20
No SpikeArrest policy is applied Proxy Code Quality DoS Protection CWE-770
Unreachable FaultRule Target Proxy Code Quality CWE-561
Unreachable Flow Target Proxy Code Quality CWE-561
Unreachable RouteRule Proxy Code Quality CWE-561
Low
Missing security headers Proxy Secure Configuration CWE-523
No mask configuration for the proxy Proxy Code Quality
Overcomplicated or malformed condition Step RouteRule Flow Code Quality CWE-570 CWE-571
Info
Missing API versioning Proxy Secure Configuration CWE-710
Policy is not linked to step Proxy Code Quality CWE-561