Internet-exposed
Posture
critical
2
high
4
medium
6
low
4
Ownership
Findings (17)
medium
SSRF in webhook fetcher
CheckmarxSAST
triaged
7.9
high
SSRF in webhook fetcher
tfsecIaC
accepted
7.9
low
Hardcoded AWS access key in source
CheckovIaC
triaged
5
high
S3 bucket publicly readable
tfsecIaC
false positive
7.6
info
Log4Shell vulnerable dependency
ProwlerCSPM
triaged
6.4
high
S3 bucket publicly readable
TruffleHogSecrets
false positive
8.9
low
Dependency confusion risk on internal package
SnykSCA
open
7.6
critical
SQL Injection in user-input handler
CodeQLSAST
accepted
4.9
medium
SQL Injection in user-input handler
Cloudflare WAFWAF
false positive
7.8
medium
S3 bucket publicly readable
GitleaksSecrets
triaged
8.3
medium
Hardcoded AWS access key in source
SemgrepSAST
open
9.5
critical
Unencrypted RDS snapshot
OWASP ZAPDAST
triaged
10
medium
Path traversal in file download endpoint
WizCSPM
triaged
8.4
low
Unencrypted RDS snapshot
OWASP ZAPDAST
false positive
5.6