Skip to content
Start here

Retrieves Security Center Issues

Deprecated
client.intel.attackSurfaceReport.issues.list(IssueListParams { account_id, dismissed, issue_class, 11 more } params, RequestOptionsoptions?): V4PagePagination<IssueListResponse { count, issues, page, per_page } >
GET/accounts/{account_id}/intel/attack-surface-report/issues

Lists all Security Center issues for the account, showing active security problems requiring attention.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
Intel WriteIntel Read
ParametersExpand Collapse
params: IssueListParams { account_id, dismissed, issue_class, 11 more }
account_id: string

Path param: Identifier.

maxLength32
dismissed?: boolean

Query param

issue_class?: Array<string>

Query param

issueClassNeq?: Array<string>

Query param

issue_type?: Array<IssueType>

Query param

One of the following:
"compliance_violation"
"email_security"
"exposed_infrastructure"
"insecure_configuration"
"weak_authentication"
"configuration_suggestion"
issueTypeNeq?: Array<IssueType>

Query param

One of the following:
"compliance_violation"
"email_security"
"exposed_infrastructure"
"insecure_configuration"
"weak_authentication"
"configuration_suggestion"
page?: number

Query param: Specifies the current page within paginated list of results.

per_page?: number

Query param: Sets the number of results per page of results.

maximum1000
minimum1
product?: Array<string>

Query param

productNeq?: Array<string>

Query param

severity?: Array<SeverityQueryParam>

Query param

One of the following:
"low"
"moderate"
"critical"
severityNeq?: Array<SeverityQueryParam>

Query param

One of the following:
"low"
"moderate"
"critical"
subject?: Array<string>

Query param

subjectNeq?: Array<string>

Query param

ReturnsExpand Collapse
IssueListResponse { count, issues, page, per_page }
count?: number

Indicates the total number of results.

issues?: Array<Issue>
id?: string
dismissed?: boolean
has_extended_context?: boolean

Indicates whether the insight has a large payload that requires fetching via the context endpoint.

issue_class?: string
issue_type?: IssueType
One of the following:
"compliance_violation"
"email_security"
"exposed_infrastructure"
"insecure_configuration"
"weak_authentication"
"configuration_suggestion"
payload?: Payload { detection_method, zone_tag }
detection_method?: string

Describes the method used to detect insight.

zone_tag?: string
resolve_text?: string
severity?: "Low" | "Moderate" | "Critical"
One of the following:
"Low"
"Moderate"
"Critical"
since?: string
formatdate-time
status?: "active" | "resolved"

The current status of the insight.

One of the following:
"active"
"resolved"
subject?: string
timestamp?: string
formatdate-time
user_classification?: "false_positive" | "accept_risk" | "other" | null

User-defined classification for the insight. Can be ‘false_positive’, ‘accept_risk’, ‘other’, or null.

One of the following:
"false_positive"
"accept_risk"
"other"
page?: number

Specifies the current page within paginated list of results.

per_page?: number

Sets the number of results per page of results.

maximum1000
minimum1

Retrieves Security Center Issues

import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

// Automatically fetches more pages as needed.
for await (const issueListResponse of client.intel.attackSurfaceReport.issues.list({
  account_id: '023e105f4ecef8ad9ca31a8372d0c353',
})) {
  console.log(issueListResponse.count);
}
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "count": 1,
    "issues": [
      {
        "id": "id",
        "dismissed": false,
        "has_extended_context": false,
        "issue_class": "always_use_https_not_enabled",
        "issue_type": "compliance_violation",
        "payload": {
          "detection_method": "We detected security rules referencing multiple IP addresses directly in the rules.",
          "zone_tag": "zone_tag"
        },
        "resolve_link": "resolve_link",
        "resolve_text": "resolve_text",
        "severity": "Low",
        "since": "2019-12-27T18:11:19.117Z",
        "status": "active",
        "subject": "example.com",
        "timestamp": "2019-12-27T18:11:19.117Z",
        "user_classification": "false_positive"
      }
    ],
    "page": 1,
    "per_page": 25
  }
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "count": 1,
    "issues": [
      {
        "id": "id",
        "dismissed": false,
        "has_extended_context": false,
        "issue_class": "always_use_https_not_enabled",
        "issue_type": "compliance_violation",
        "payload": {
          "detection_method": "We detected security rules referencing multiple IP addresses directly in the rules.",
          "zone_tag": "zone_tag"
        },
        "resolve_link": "resolve_link",
        "resolve_text": "resolve_text",
        "severity": "Low",
        "since": "2019-12-27T18:11:19.117Z",
        "status": "active",
        "subject": "example.com",
        "timestamp": "2019-12-27T18:11:19.117Z",
        "user_classification": "false_positive"
      }
    ],
    "page": 1,
    "per_page": 25
  }
}