v1
latestOpenAPI 3.0.32026-07-134103031.5 MBPartial Update Target's Finding
Path parameters
Identifier of the target.
Request body
Target scanned to find vulnerabilities.
Scans that originated the vulnerability finding.
Description of how to fix the vulnerability.
Evidence with proof of the vulnerability finding.
Extra details about the vulnerability finding.
Definition of the vulnerability.
URL of the vulnerability finding. For example, "http://www.example.com/user/show-details". The maximum length is 66000 characters.
URL path of the vulnerability finding. For example, "user/show-details".
HTTP method used in the request:
- get - GET
- post - POST
- trace - TRACE
- options - OPTIONS
- put - PUT
- delete - DELETE
Insertion point of the parameter:
- cookie - Cookie
- parameter - Parameter
- arbitrary_url_param - Parameter
- header - Header
- url_folder - URL Path
- url_filename - URL Path
- json_parameter - JSON Parameter
- request_body - Request Body
- multipart_parameter - Multipart Parameter
- graphql_parameter - GraphQL Parameter
- non_standard_parameter - Non Standard Parameter
Name of the inserted parameter.
The maximum length is 1024 characters.
Value of the inserted parameter.
GraphQL operation name, if applicable.
GraphQL operation type (query, mutation, subscription), if applicable.
Query parameters of the vulnerability finding, in JSON format. For example, "{'name': ['Joe Smith'], 'phone': ['+919999999999', '+628888888888']}"
User who is assigned to fix the vulnerability.
State of the vulnerability finding:
(Read more about the meaning of vulnerability findings states)
- notfixed - Not Fixed
- invalid - Invalid
- accepted - Accepted
- fixed - Fixed
Severity of the vulnerability finding:
- 10 - low
- 20 - medium
- 30 - high
- 40 - critical
Score of the vulnerability finding according to the Common Vulnerability Scoring System (CVSS).
Vector with the metrics of the score of the vulnerability finding according to the Common Vulnerability Scoring System (CVSS).
Date and time of when the vulnerability was last found, in ISO 8601 UTC format. For example, "2023-08-09T13:27:43.8208302"
If true, the vulnerability will be retested.
If, after the retest, the vulnerability is no longer found, the vulnerability finding is marked as fixed. Otherwise, it is marked as not fixed.
If true, this is a newly found vulnerability. If false, this vulnerability has been found in previous scans.
Some findings we're unsure are valid and need a manual validation step.
- notrequired - not required
- pending - pending review
- rejected - rejected after review
- accepted - accepted after review
User's reason for finding's review.
Timestamp of the Finding's creation.
Date and time of the last change, in ISO 8601 UTC format.
For example, "2023-08-09T13:27:43.8208302".
Comment on the object.
Reason for changing the Finding state to 'invalid' or 'accepted'.
Expiration date of the acceptance. Required if the account setting 'Require expiration date on acceptance' is set.
Name of the person or entity approving the acceptance. Required if the account setting 'Require approval name on acceptance' is set.
Date of the approval of the acceptance. Required if the account setting 'Require approval date on acceptance' is set.
Response
Global ID in the format: <TARGET_ID>-<FINDING_ID>
Scans that originated the vulnerability finding.
Description of how to fix the vulnerability.
Evidence with proof of the vulnerability finding.
Extra details about the vulnerability finding.
URL of the vulnerability finding. For example, "http://www.example.com/user/show-details". The maximum length is 66000 characters.
URL path of the vulnerability finding. For example, "user/show-details".
HTTP method used in the request:
- get - GET
- post - POST
- trace - TRACE
- options - OPTIONS
- put - PUT
- delete - DELETE
Insertion point of the parameter:
- cookie - Cookie
- parameter - Parameter
- arbitrary_url_param - Parameter
- header - Header
- url_folder - URL Path
- url_filename - URL Path
- json_parameter - JSON Parameter
- request_body - Request Body
- multipart_parameter - Multipart Parameter
- graphql_parameter - GraphQL Parameter
- non_standard_parameter - Non Standard Parameter
Name of the inserted parameter.
The maximum length is 1024 characters.
Value of the inserted parameter.
GraphQL operation name, if applicable.
GraphQL operation type (query, mutation, subscription), if applicable.
Query parameters of the vulnerability finding, in JSON format. For example, "{'name': ['Joe Smith'], 'phone': ['+919999999999', '+628888888888']}"
State of the vulnerability finding:
(Read more about the meaning of vulnerability findings states)
- notfixed - Not Fixed
- invalid - Invalid
- accepted - Accepted
- fixed - Fixed
Severity of the vulnerability finding:
- 10 - low
- 20 - medium
- 30 - high
- 40 - critical
Score of the vulnerability finding according to the Common Vulnerability Scoring System (CVSS).
Vector with the metrics of the score of the vulnerability finding according to the Common Vulnerability Scoring System (CVSS).
Date and time of when the vulnerability was last found, in ISO 8601 UTC format. For example, "2023-08-09T13:27:43.8208302"
If true, the vulnerability will be retested.
If, after the retest, the vulnerability is no longer found, the vulnerability finding is marked as fixed. Otherwise, it is marked as not fixed.
If true, this is a newly found vulnerability. If false, this vulnerability has been found in previous scans.
Some findings we're unsure are valid and need a manual validation step.
- notrequired - not required
- pending - pending review
- rejected - rejected after review
- accepted - accepted after review
User's reason for finding's review.
Timestamp of the Finding's creation.
Date and time of the last change, in ISO 8601 UTC format.
For example, "2023-08-09T13:27:43.8208302".
Comment on the object.
Reason for changing the Finding state to 'invalid' or 'accepted'.
Expiration date of the acceptance. Required if the account setting 'Require expiration date on acceptance' is set.
Name of the person or entity approving the acceptance. Required if the account setting 'Require approval name on acceptance' is set.
Date of the approval of the acceptance. Required if the account setting 'Require approval date on acceptance' is set.