Flow Target AccessControl AssignMessage
Name Severity Scopes Tags Links
Bypassing AccessControl policy via True-Client-IP header Critical AccessControl Data Validation CWE-290
Connection to the system is not encrypted Critical ServiceCallout MessageLogging Target Data in Transit CWE-319
Lack of certificate validation Critical ServiceCallout MessageLogging Target Data in Transit CWE-295
AssignMessage request parameters pollution High AssignMessage Data Validation CWE-20
Flow accepts confidential data as URL parameters High Flow PreFlow Data in Transit CWE-598
JSONThreatProtection policy is not applied to a request body with JSON type High Flow Data Validation CWE-502 CWE-20
No TLS protocol specified in connection definition High ServiceCallout MessageLogging Target Data in Transit CWE-327
Use of weak hash algorithms High AssignMessage HMAC JavaScript Secure Configuration CWE-327
AccessControl allows all IPs Medium AccessControl Data Validation CWE-290
Condition has undefined variables Medium Step RouteRule Flow Code Quality CWE-570 CWE-571
Flow accepts requests with any method Medium Flow Data Validation CWE-749
Flow doesn't limit HTTP methods correctly Medium Flow Data Validation CWE-749
Lack of DefaultFaultRule Medium Target Proxy Error Handling CWE-390
MatchesPath is applied to a static parameter Medium Target Proxy Code Quality Data Validation CWE-20
Unreachable FaultRule Medium Target Proxy Code Quality CWE-561
Unreachable Flow Medium Target Proxy Code Quality CWE-561
Overcomplicated or malformed condition Low Step RouteRule Flow Code Quality CWE-570 CWE-571