Get reviewed vulnerability report
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos/{repo_id}/scans/{scan_id}/report
Gets the repository projection of the active operator-reviewed scan report. scan_id is the customer scan’s stable request ID.
Security
API Token
The preferred authorization scheme for interacting with the Cloudflare API. Create a token.
Example:
API Email + API Key
The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.
Example:
The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.
Example:
Get reviewed vulnerability report
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/managed-defense/vulnerability-discovery/repos/$REPO_ID/scans/$SCAN_ID/report \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"{
"errors": [
{
"code": 1000,
"message": "message",
"documentation_url": "documentation_url",
"source": {
"pointer": "pointer"
}
}
],
"messages": [
{
"code": 1000,
"message": "message",
"documentation_url": "documentation_url",
"source": {
"pointer": "pointer"
}
}
],
"result": {
"publication": {
"published_at": "2019-12-27T18:11:19.117Z",
"revision_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
"version": 1
},
"report": {
"findings": [
{
"id": "x",
"conditions": [
"string"
],
"cwe": "x",
"impact": "x",
"location": {
"file": "x",
"line": 1,
"route": "route"
},
"reachability": [
{
"consumer": "x",
"reachable": true,
"via": "via"
}
],
"remediation": {
"code_changes": "code_changes",
"strategy": "x"
},
"root_cause": "x",
"severity": "critical",
"severity_basis": "x",
"summary": "x",
"telemetry": {
"references": [
"x"
],
"state": "no_route"
},
"title": "x",
"trace": [
{
"line": 1,
"path": "x",
"scope": "scope",
"why": "why"
}
],
"waf_rules": {
"broad": {
"action": "block",
"confidence": "low",
"description": "x",
"expression": "x",
"false_positive_risk": "x",
"name": "x",
"rationale": "x"
},
"targeted": {
"action": "block",
"confidence": "low",
"description": "x",
"expression": "x",
"false_positive_risk": "x",
"name": "x",
"rationale": "x"
}
},
"attacker_position": "external",
"external_links": [
{
"title": "x",
"url": "https://example.com"
}
],
"open_question": "open_question",
"proof_method": "structural",
"proof_state": "closed"
}
],
"overall_severity": "critical",
"repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
"repository_name": "x",
"summary": "x",
"traffic_context": {
"http": {
"error_paths": [
{
"id": "x",
"hits": 0,
"host": "x",
"path": "x",
"status": 100
}
],
"hot_paths": [
{
"id": "x",
"hits": 0,
"host": "x",
"path": "x",
"top_status": 100
}
],
"request_volume": 0
},
"target": {
"hosts": [
"x"
],
"kind": "worker",
"telemetry_window": {
"end": "2019-12-27T18:11:19.117Z",
"start": "2019-12-27T18:11:19.117Z"
}
},
"waf": {
"hit_volume": 0,
"rules": [
{
"id": "x",
"hit_volume": 0,
"paths": [
{
"id": "x",
"hit_volume": 0,
"host": "x",
"path": "x"
}
],
"rule_id": "x",
"rule_version": 0
}
]
},
"web_assets": {
"operations": [
{
"id": "x",
"endpoint": "x",
"host": "x",
"method": "x",
"risk_labels": [
{
"description": "description",
"name": "x"
}
],
"performance": {
"avg_origin_latency_ms": 0,
"error_rate": 0,
"estimated_requests": 0
}
}
],
"paths": [
{
"id": "x",
"avg_origin_latency_ms": 0,
"error_rate": 0,
"estimated_requests": 0,
"host": "x",
"path": "x"
}
],
"risk_types": [
{
"description": "description",
"name": "x",
"operation_count": 0
}
]
}
},
"external_links": [
{
"title": "x",
"url": "https://example.com"
}
],
"limitations": [
"x"
]
},
"repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
"scan_id": "x"
},
"success": true
}Returns Examples
{
"errors": [
{
"code": 1000,
"message": "message",
"documentation_url": "documentation_url",
"source": {
"pointer": "pointer"
}
}
],
"messages": [
{
"code": 1000,
"message": "message",
"documentation_url": "documentation_url",
"source": {
"pointer": "pointer"
}
}
],
"result": {
"publication": {
"published_at": "2019-12-27T18:11:19.117Z",
"revision_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
"version": 1
},
"report": {
"findings": [
{
"id": "x",
"conditions": [
"string"
],
"cwe": "x",
"impact": "x",
"location": {
"file": "x",
"line": 1,
"route": "route"
},
"reachability": [
{
"consumer": "x",
"reachable": true,
"via": "via"
}
],
"remediation": {
"code_changes": "code_changes",
"strategy": "x"
},
"root_cause": "x",
"severity": "critical",
"severity_basis": "x",
"summary": "x",
"telemetry": {
"references": [
"x"
],
"state": "no_route"
},
"title": "x",
"trace": [
{
"line": 1,
"path": "x",
"scope": "scope",
"why": "why"
}
],
"waf_rules": {
"broad": {
"action": "block",
"confidence": "low",
"description": "x",
"expression": "x",
"false_positive_risk": "x",
"name": "x",
"rationale": "x"
},
"targeted": {
"action": "block",
"confidence": "low",
"description": "x",
"expression": "x",
"false_positive_risk": "x",
"name": "x",
"rationale": "x"
}
},
"attacker_position": "external",
"external_links": [
{
"title": "x",
"url": "https://example.com"
}
],
"open_question": "open_question",
"proof_method": "structural",
"proof_state": "closed"
}
],
"overall_severity": "critical",
"repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
"repository_name": "x",
"summary": "x",
"traffic_context": {
"http": {
"error_paths": [
{
"id": "x",
"hits": 0,
"host": "x",
"path": "x",
"status": 100
}
],
"hot_paths": [
{
"id": "x",
"hits": 0,
"host": "x",
"path": "x",
"top_status": 100
}
],
"request_volume": 0
},
"target": {
"hosts": [
"x"
],
"kind": "worker",
"telemetry_window": {
"end": "2019-12-27T18:11:19.117Z",
"start": "2019-12-27T18:11:19.117Z"
}
},
"waf": {
"hit_volume": 0,
"rules": [
{
"id": "x",
"hit_volume": 0,
"paths": [
{
"id": "x",
"hit_volume": 0,
"host": "x",
"path": "x"
}
],
"rule_id": "x",
"rule_version": 0
}
]
},
"web_assets": {
"operations": [
{
"id": "x",
"endpoint": "x",
"host": "x",
"method": "x",
"risk_labels": [
{
"description": "description",
"name": "x"
}
],
"performance": {
"avg_origin_latency_ms": 0,
"error_rate": 0,
"estimated_requests": 0
}
}
],
"paths": [
{
"id": "x",
"avg_origin_latency_ms": 0,
"error_rate": 0,
"estimated_requests": 0,
"host": "x",
"path": "x"
}
],
"risk_types": [
{
"description": "description",
"name": "x",
"operation_count": 0
}
]
}
},
"external_links": [
{
"title": "x",
"url": "https://example.com"
}
],
"limitations": [
"x"
]
},
"repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
"scan_id": "x"
},
"success": true
}