Posture
critical
5
high
6
medium
9
low
8
Ownership
Findings (36)
info
Hardcoded AWS access key in source
Scout SuiteCSPM
open
9.3
critical
Missing rate limiting on /login
Burp Pro PenTestPenTest
false positive
6.1
low
Missing rate limiting on /login
CodeQLSAST
triaged
8.8
medium
Terraform module pins old AMI with CVEs
CodeQLSAST
accepted
4.7
info
Race condition in payment idempotency
GrypeContainer
triaged
8.8
info
Container running as root
DependabotSCA
open
7.1
low
Missing rate limiting on /login
TruffleHogSecrets
triaged
5.3
low
IAM role with wildcard permissions
GitleaksSecrets
accepted
4.9
low
Insecure deserialization in message queue consumer
Contrast RASPRASP
open
8
high
Race condition in payment idempotency
TruffleHogSecrets
open
4.3
low
Missing rate limiting on /login
SnykSCA
accepted
5.4
medium
JWT signed with weak HS256 secret
GrypeContainer
open
4
high
Cross-site Scripting in profile renderer
SnykSCA
false positive
4
critical
IAM role with wildcard permissions
SonarQubeSAST
triaged
7.3
info
Unencrypted RDS snapshot
TruffleHogSecrets
open
6.5
medium
Dependency confusion risk on internal package
Burp Pro PenTestPenTest
triaged
5.9
medium
Dependency confusion risk on internal package
TrivyContainer
open
5.8
info
Cross-site Scripting in profile renderer
GitleaksSecrets
open
9.9
high
Path traversal in file download endpoint
Burp Pro PenTestPenTest
open
6.9
medium
Dependency confusion risk on internal package
DependabotSCA
open
4.6
high
Dependency confusion risk on internal package
WizCSPM
open
9.4
info
Missing CSP header on auth pages
Burp Pro PenTestPenTest
open
7
high
Open Redis without auth
TrivyContainer
accepted
6
medium
Insecure deserialization in message queue consumer
CheckovIaC
triaged
8.8
medium
Dependency confusion risk on internal package
tfsecIaC
triaged
6
low
Missing rate limiting on /login
TrivyContainer
accepted
8
info
Outdated lodash with prototype pollution
CodeQLSAST
false positive
8.5
high
Container running as root
CodeQLSAST
triaged
5.2
medium
Missing CSP header on auth pages
SemgrepSAST
open
6.8
info
Terraform module pins old AMI with CVEs
Burp SuiteDAST
open
7.9