Low Medium
Name Severity Scopes Tags Links
Unreachable RouteRule Medium Proxy Code Quality CWE-561
Unreachable Flow Medium Target Proxy Code Quality CWE-561
Unreachable FaultRule Medium Target Proxy Code Quality CWE-561
Step operates undefined flow variables Low Step Code Quality CWE-457
Sharedflow has not beeing scanned by CodeSent Low FlowCallout Code Quality
ServiceCallout policy uses default message object as a response Medium ServiceCallout Code Quality CWE-200
ServiceCallout policy uses default message object as a request Medium ServiceCallout Code Quality CWE-200
Private flow variable is written into public one Medium Step Data at Rest CWE-532
Policy errors are not caught Low Step Error Handling CWE-390
Overcomplicated or malformed condition Low Step RouteRule Flow Code Quality CWE-570 CWE-571
No mask configuration for the proxy Low Proxy Code Quality
No SpikeArrest policy is applied Medium Proxy Code Quality DoS Protection CWE-770
Missing security headers Low Proxy Secure Configuration CWE-523
MatchesPath is applied to a static parameter Medium Target Proxy Code Quality Data Validation CWE-20
Masked flow variable is written into unmasked one Medium Step Data at Rest CWE-532
Lack of DefaultFaultRule Medium Target Proxy Error Handling CWE-390
Insecure token expiration configuration Medium OAuthV2 Secure Configuration CWE-613
Insecure JSONThreatProtection policy Medium JSONThreatProtection Code Quality Data Validation CWE-770 CWE-20
Flow doesn't limit HTTP methods correctly Medium Flow Data Validation CWE-749
Flow accepts requests with any method Medium Flow Data Validation CWE-749