Flow JavaScript Proxy
Name Severity Scopes Tags Links
Use of weak hash algorithms High AssignMessage HMAC JavaScript Secure Configuration CWE-327
Unreachable RouteRule Medium Proxy Code Quality CWE-561
Unreachable Flow Medium Target Proxy Code Quality CWE-561
Unreachable FaultRule Medium Target Proxy Code Quality CWE-561
Resource is not linked to a policy Info Proxy Code Quality CWE-561
Proxy doesn't have default flow High Proxy Code Quality Data Validation CWE-20
Policy is not linked to step Info Proxy Code Quality CWE-561
Overcomplicated or malformed condition Low Step RouteRule Flow Code Quality CWE-570 CWE-571
No mask configuration for the proxy Low Proxy Code Quality
No SpikeArrest policy is applied Medium Proxy Code Quality DoS Protection CWE-770
Missing security headers Low Proxy Secure Configuration CWE-523
Missing API versioning Info Proxy Secure Configuration CWE-710
MatchesPath is applied to a static parameter Medium Target Proxy Code Quality Data Validation CWE-20
Lack of DefaultFaultRule Medium Target Proxy Error Handling CWE-390
JSONThreatProtection policy is not applied to a request body with JSON type High Flow Data Validation CWE-502 CWE-20
Flow doesn't limit HTTP methods correctly Medium Flow Data Validation CWE-749
Flow accepts requests with any method Medium Flow Data Validation CWE-749
Flow accepts confidential data as URL parameters High Flow PreFlow Data in Transit CWE-598
Condition has undefined variables Medium Step RouteRule Flow Code Quality CWE-570 CWE-571
Authorization header is not removed before the request is sent to target system High Proxy Data in Transit CWE-201