Name Severity Scopes Tags Links
Missing API versioning Info Proxy Secure Configuration CWE-710
Policy is not linked to step Info Proxy Code Quality CWE-561
Resource is not linked to a policy Info Proxy Code Quality CWE-561
Unused flow variables Info Step Code Quality CWE-563
Cache lookup variable is overwritten Low Step Code Quality CWE-472
Missing security headers Low Proxy Secure Configuration CWE-523
No mask configuration for the proxy Low Proxy Code Quality
Overcomplicated or malformed condition Low Step RouteRule Flow Code Quality CWE-570 CWE-571
Policy errors are not caught Low Step Error Handling CWE-390
Sharedflow has not beeing scanned by CodeSent Low FlowCallout Code Quality
Step operates undefined flow variables Low Step Code Quality CWE-457
AccessControl allows all IPs Medium AccessControl Data Validation CWE-290
Condition has undefined variables Medium Step RouteRule Flow Code Quality CWE-570 CWE-571
Error flow variable is set but not checked in request phase Medium Step Error Handling CWE-390
Flow accepts requests with any method Medium Flow Data Validation CWE-749
Flow doesn't limit HTTP methods correctly Medium Flow Data Validation CWE-749
Insecure JSONThreatProtection policy Medium JSONThreatProtection Code Quality Data Validation CWE-770 CWE-20
Insecure token expiration configuration Medium OAuthV2 Secure Configuration CWE-613
Lack of DefaultFaultRule Medium Target Proxy Error Handling CWE-390
Masked flow variable is written into unmasked one Medium Step Data at Rest CWE-532