Title: SLA Vulnerability on GET:/api/v1/issues/product/{projectId}
Project: Sanity 7th July
Description: This took more time to return than the expected SLA. It might impact the overall performance of the application.
Assertion
Performance SLA scanning allows endpoint performance monitoring from one or more regions based on your customer usage. Keep historical data and identify bottlenecks before they become much worse.Risk: SLA
Severity: Medium
API Endpoint: http://95.217.118.53:8080/api/v1/issues/product/12345?page=1001&pageSize=1001
Environment: Master
Playbook: ApiV1IssuesProductProjectidGetQueryParamPageSla
Researcher: [apisec Bot]
Title: SLA Vulnerability on GET:/api/v1/issues/product/{projectId} Project: Sanity 7th July Description: This took more time to return than the expected SLA. It might impact the overall performance of the application.
Assertion Performance SLA scanning allows endpoint performance monitoring from one or more regions based on your customer usage. Keep historical data and identify bottlenecks before they become much worse.Risk: SLA Severity: Medium API Endpoint: http://95.217.118.53:8080/api/v1/issues/product/12345?page=1001&pageSize=1001 Environment: Master Playbook: ApiV1IssuesProductProjectidGetQueryParamPageSla Researcher: [apisec Bot]
QUICK TIPS
Suggestion: Improve the performance of this call. Effort Estimate: 1.0 Hrs Wire Logs: 00:46:48 [D] [AVIPPGQPPSla] : Endpoint [http://95.217.118.53:8080/api/v1/issues/product/12345?page=1001&pageSize=1001] 00:46:48 [D] [AVIPPGQPPSla] : Method [GET] 00:46:48 [D] [AVIPPGQPPSla] : Authorization [Default] 00:46:48 [D] [AVIPPGQPPSla] : Request headers [[Accept:"application/json", Content-Type:"application/json", Authorization=[**]]] 00:46:48 [D] [AVIPPGQPPSla] : Request [] 00:46:48 [D] [AVIPPGQPPSla] : Status code [200] 00:46:48 [D] [AVIPPGQPPSla] : Response headers [[X-Content-Type-Options:"nosniff", X-XSS-Protection:"1; mode=block", Cache-Control:"no-cache, no-store, max-age=0, must-revalidate", Pragma:"no-cache", Expires:"0", X-Frame-Options:"DENY", Set-Cookie:"SESSION=MTIwYmJkNDQtYjhlYS00ZGMxLWIxY2EtMmViNDU1OTBiNGQz; Path=/; HttpOnly", Content-Type:"application/json;charset=UTF-8", Transfer-Encoding:"chunked", Date:"Tue, 17 Aug 2021 00:46:47 GMT"]] 00:46:48 [D] [AVIPPGQPPSla] : Response [{ "requestId" : "None", "requestTime" : "2021-08-17T00:46:48.409+0000", "errors" : true, "messages" : [ { "type" : "ERROR", "key" : "", "value" : "findByProjectId.arg2: must be less than or equal to 20" } ], "data" : null, "totalPages" : 0, "totalElements" : 0 }] 00:46:48 [D] [AVIPPGQPPSla] : Response time [1191] 00:46:48 [D] [AVIPPGQPPSla] : Response size [228] 00:46:48 [E] [AVIPPGQPPSla] : Assertion [@StatusCode == 200 AND @ResponseTime < 1000] resolved-to [200 == 200 AND 1191 < 1000] result [Failed]
IMPORTANT LINKS
Vulnerability Details: https://cloud.fxlabs.io/#/app/projects/8a8093567a8012b6017a803bf31114fd/dashboard/8a80932a7b4f1826017b51933f1165ae/details
Project: https://cloud.fxlabs.io/#/app/projects/8a8093567a8012b6017a803bf31114fd/allScans
Environment: https://cloud.fxlabs.io/#/app/projects/8a8093567a8012b6017a803bf31114fd/environments/8a8093567a8012b6017a803bf3181500/edit
Scan Dashboard: https://cloud.fxlabs.io/#/app/projects/8a8093567a8012b6017a803bf31114fd/profiles/8a8093567a8012b6017a803c070d16cb/runs/8a80932a7b4f1826017b518e9f6b5ddd
Playbook: https://cloud.fxlabs.io/#/app/projects/8a8093567a8012b6017a803bf31114fd/playbooks/ApiV1IssuesProductProjectidGetQueryParamPageSla
Coverage: https://cloud.fxlabs.io/#/app/projects/8a8093567a8012b6017a803bf31114fd/categories
Code Sample: https://cloud.fxlabs.io/#/app/projects/8a8093567a8012b6017a803bf31114fd/dashboard/8a80932a7b4f1826017b51933f1165ae/codesamples
PS: Please contact support@apisec.ai for apisec access and login issues.
--- apisec Bot ---