Findings

All open vulnerability findings across applications.

Critical
14
High
17
Medium
48
Low
29
IDTitleSevScannerAppAssigneeAgeSLAStatus
FND-0000SQL injection in order lookuplowContainerdata-lakeSara Okafor15d75d leftin progress
FND-0001Hardcoded AWS access key in repolowCSPMcheckout-webMarcus Lin79d11d leftaccepted
FND-0002Outdated openssl (CVE-2024-0727)highPentestk8s-platformNoor Idris0d30d leftin progress
FND-0003Cross-site scripting in support formcriticalSASTledger-serviceAisha Banda5d2d leftin progress
FND-0004S3 bucket world-readablecriticalContaineridentity-svcTomas Hill72d65d overopen
FND-0005Container running as rootcriticalCSPMk8s-platformMarcus Lin22d15d overopen
FND-0006Weak TLS cipher suites enabledmediumSecretsk8s-platformTomas Hill18dMetresolved
FND-0007Missing CSRF token on POST endpointcriticalPentestdata-lakeRiley Chen83dMetresolved
FND-0008Log4j vulnerable version detectedmediumSASTpayments-apiTomas Hill1d59d leftaccepted
FND-0009IAM role with AdministratorAccesslowContainermarketing-webMarcus Lin25d65d leftopen
FND-0010Unencrypted RDS instancemediumSASTmarketing-webBen Carter50d10d leftaccepted
FND-0011Insecure deserialization in webhook handlermediumSCAdata-lakeNoor Idris26d34d leftin progress
FND-0012Path traversal in file downloadinfoCSPMk8s-platformRiley Chen26d64d leftaccepted
FND-0013Race condition in payment idempotencymediumSecretspayments-apiMei Wong42dMetresolved
FND-0014JWT signature not verifiedinfoPentestdata-lakeNoor Idris20d70d leftopen
FND-0015Open redirect in login flowlowDASTdata-lakeTomas Hill79d11d lefttriaged
FND-0016Sensitive data in URL paramshighSCApayments-apiMarcus Lin66d36d overaccepted
FND-0017Dependency confusion in private registryhighCSPMcheckout-webMarcus Lin4dMetresolved
FND-0018Public RDP exposed on EC2mediumSCApayments-apiBen Carter19d41d lefttriaged
FND-0019Default credentials on internal dashboardhighCSPMledger-serviceNoor Idris35d5d overopen
FND-0020GraphQL introspection enabled in prodlowSCAmarketing-webNoor Idris29d61d lefttriaged
FND-0021Lambda function with overly broad permissionsmediumSCAledger-serviceMarcus Lin28d32d lefttriaged
FND-0022Secret committed in git historylowSASTledger-serviceSara Okafor3d87d lefttriaged
FND-0023Insecure direct object referencemediumSecretsmobile-iosAisha Banda39dMetresolved
FND-0024Server-side request forgery in importermediumSecretsidentity-svcSara Okafor13d47d leftaccepted
FND-0025Prototype pollution in lodash <4.17.21highCSPMmarketing-webMei Wong44d14d overtriaged
FND-0026Missing rate limit on auth endpointlowSASTcheckout-webMarcus Lin45d45d leftopen
FND-0027SQL injection in order lookuplowContainermobile-iosTomas Hill53dMetresolved
FND-0028Hardcoded AWS access key in repolowSCAmarketing-webTomas Hill56dMetresolved
FND-0029Outdated openssl (CVE-2024-0727)mediumSASTdata-lakeBen Carter65d5d overopen
FND-0030Cross-site scripting in support formlowDASTcheckout-webTomas Hill4d86d leftopen
FND-0031S3 bucket world-readablelowContainercheckout-webSara Okafor59dMetresolved
FND-0032Container running as rootmediumSCAledger-serviceAisha Banda27d33d leftin progress
FND-0033Weak TLS cipher suites enabledmediumPentestidentity-svcRiley Chen12d48d leftin progress
FND-0034Missing CSRF token on POST endpointinfoSecretsidentity-svcRiley Chen45d45d leftopen
FND-0035Log4j vulnerable version detectedcriticalDASTdata-lakeRiley Chen50d43d overtriaged
FND-0036IAM role with AdministratorAccesslowCSPMmobile-iosAisha Banda47dMetresolved
FND-0037Unencrypted RDS instancehighDASTdata-lakeSara Okafor60d30d overopen
FND-0038Insecure deserialization in webhook handlermediumDASTmobile-iosAisha Banda48d12d lefttriaged
FND-0039Path traversal in file downloadmediumSecretsmarketing-webSara Okafor61d1d overin progress