Low Medium
Name Scopes Tags Links
Medium
Unreachable RouteRule Proxy Code Quality CWE-561
Unreachable Flow Target Proxy Code Quality CWE-561
Unreachable FaultRule Target Proxy Code Quality CWE-561
SpikeArrest uses user-controlled identifiers Step Code Quality Data Validation DoS Protection CWE-770
ServiceCallout policy uses default message object as a response ServiceCallout Code Quality CWE-200
ServiceCallout policy uses default message object as a request ServiceCallout Code Quality CWE-200
No SpikeArrest policy is applied Proxy Code Quality DoS Protection CWE-770
MatchesPath is applied to a static parameter Target Proxy Code Quality Data Validation CWE-20
Masked flow variable is written into unmasked one Step Data at Rest CWE-532
Lack of DefaultFaultRule Target Proxy Error Handling CWE-390
Insecure token expiration configuration OAuthV2 Secure Configuration CWE-613
Insecure JSONThreatProtection policy JSONThreatProtection Code Quality Data Validation CWE-770 CWE-20
Flow doesn't limit HTTP methods correctly Flow Data Validation CWE-749
Flow accepts requests with any method Flow Data Validation CWE-749
Low
Step operates undefined flow variables Step Code Quality CWE-457
Sharedflow has not beeing scanned by CodeSent FlowCallout Code Quality
Policy errors are not caught Step Error Handling CWE-390
Overcomplicated or malformed condition Step RouteRule Flow Code Quality CWE-570 CWE-571
No mask configuration for the proxy Proxy Code Quality
Missing security headers Proxy Secure Configuration CWE-523