• Home
  • CodeSent for Apigee
    • Features
    • Rules
    • API
  • Demo
  • Pricing
  • Blog
  • Courses
  • Contacts
  • Sign in
  • Get a demo
    • Home
    • CodeSent for Apigee
      • Features
      • Rules
      • API
    • Demo
    • Pricing
    • Blog
    • Courses
    • Contacts
  • Sign in
  • Get a demo
  1. Rules
  • Group by:
  • None
    None Severity
  • Filter by:
  • Severity(1/5)
    Info Low Medium High Critical
  • Tags
    Authentication & Authorisation Code Quality Data Validation Data at Rest Data in Transit DoS Protection Error Handling Secure Configuration
  • Scopes(4/22)
    ServiceCallout MessageLogging Step RouteRule Flow Target AccessControl AssignMessage BasicAuthentication Condition FlowCallout HMAC JavaScript JSONThreatProtection OAuthV2 PreFlow Proxy Quota Response SpikeArrest VerifyAPIKey XMLThreatProtection
High BasicAuthentication JavaScript Proxy SpikeArrest
Name Severity Scopes Tags Links
API Key is not removed before the request is sent to target system High Proxy Data in Transit CWE-201
Authorization header is not removed before the request is sent to target system High Proxy Data in Transit CWE-201
Proxy doesn't have default flow High Proxy Code Quality Data Validation CWE-20
SpikeArrest policy doesn't use any identifier High SpikeArrest DoS Protection CWE-770
Use of weak hash algorithms High AssignMessage HMAC JavaScript Secure Configuration CWE-327

Sentinel Strength for Secure API Gateway Code

  • ​Home
  • Features
  • Demo
  • Rules
  • Blog
  • Apigee Best Security Practices
  • Contact us

  • ​+381 637 736 053 ​
  • ​info@codesent.io
Socials
​
Copyright © CodeSent
Apigee is a registered trademark of Google LLC

We use cookies to provide you a better user experience on this website. Cookie Policy

Only essentials I agree