Posture
critical
2
high
0
medium
10
low
3
Ownership
Findings (15)
medium
Terraform module pins old AMI with CVEs
DependabotSCA
triaged
6.6
medium
Insecure deserialization in message queue consumer
Contrast RASPRASP
triaged
6.9
medium
IAM role with wildcard permissions
TruffleHogSecrets
triaged
6.4
medium
Outdated lodash with prototype pollution
SemgrepSAST
triaged
4.7
medium
Missing rate limiting on /login
Cloudflare WAFWAF
open
8.9
medium
Terraform module pins old AMI with CVEs
Contrast RASPRASP
triaged
8.3
medium
Path traversal in file download endpoint
CodeQLSAST
false positive
6.8
critical
S3 bucket publicly readable
SnykSCA
false positive
8.3
medium
Open Redis without auth
GrypeContainer
triaged
9.5
low
Cross-site Scripting in profile renderer
GitleaksSecrets
open
5.9
low
JWT signed with weak HS256 secret
GitleaksSecrets
triaged
5.2