• Home
  • CodeSent for Apigee
    • Features
    • Rules
    • API
  • Demo
  • Pricing
  • Blog
  • Contacts
  • Sign in
  • Get a demo
    • Home
    • CodeSent for Apigee
      • Features
      • Rules
      • API
    • Demo
    • Pricing
    • Blog
    • Contacts
  • Sign in
  • Get a demo
  1. Rules
  • Group by:
  • Severity
    None Severity
  • Filter by:
  • Severity
    Info Low Medium High Critical
  • Tags
    Authentication & Authorisation Code Quality Data Validation Data at Rest Data in Transit DoS Protection Error Handling Secure Configuration
  • Scopes
    ServiceCallout MessageLogging Step RouteRule Flow Target AccessControl AssignMessage BasicAuthentication Condition FlowCallout HMAC JavaScript JSONThreatProtection OAuthV2 PreFlow Proxy Quota Response SpikeArrest VerifyAPIKey XMLThreatProtection
Name Scopes Tags Links
High
User-controlled data in ServiceCallout Step Data Validation CWE-233 CWE-20
Use of weak hash algorithms AssignMessage HMAC JavaScript Secure Configuration CWE-327
Unsafe variable is used to define host Step Data Validation CWE-20
Unsafe regular expression Step Data Validation CWE-1333
Target URL is tainted by user input Step Data Validation CWE-22 CWE-233 CWE-918 CWE-20
SpikeArrest policy doesn't use any identifier SpikeArrest DoS Protection CWE-770
Request content is tainted by user input Step Data Validation CWE-20 CWE-116
Proxy doesn't have default flow Proxy Code Quality Data Validation CWE-20
Info
Unused flow variables Step Code Quality CWE-563
Resource is not linked to a policy Proxy Code Quality CWE-561
Medium
Unreachable RouteRule Proxy Code Quality CWE-561
Unreachable Flow Target Proxy Code Quality CWE-561
Unreachable FaultRule Target Proxy Code Quality CWE-561
ServiceCallout policy uses default message object as a response ServiceCallout Code Quality CWE-200
ServiceCallout policy uses default message object as a request ServiceCallout Code Quality CWE-200
Private flow variable is written into public one Step Data at Rest CWE-532
Low
Step operates undefined flow variables Step Code Quality CWE-457
Sharedflow has not beeing scanned by CodeSent FlowCallout Code Quality
Critical
Sensitive information is in the source code Step Data at Rest CWE-256 CWE-312
Request content is stringified Step Data Validation DoS Protection CWE-20
  • 1
  • 2
  • 3

Sentinel Strength for Secure API Gateway Code

  • ​Home
  • Features
  • Demo
  • Rules
  • Blog
  • Apigee Best Security Practices
  • Contact us

  • ​+381 637 736 053 ​
  • ​info@codesent.io
Socials
​
Copyright © CodeSent
Apigee is a registered trademark of Google LLC

We use cookies to provide you a better user experience on this website. Cookie Policy

Only essentials I agree