| Finding ID | Title | Source | Severity | Asset | Detected ▼ | Triage | POA&M | ||
|---|---|---|---|---|---|---|---|---|---|
| FND-0318 | Weak TLS cipher suites on internal API gatewayCBC-mode suites without forward secrecy negotiated on 443/TCP | Vulnerability Scan | Moderate | 10.42.4.20 | 2026-08-04 | Pending | — | ||
| FND-0317 | Deprecated hash algorithm in service-to-service tokensSHA-1 signatures accepted by the internal token validator | Penetration Test | High | svc-auth-01 | 2026-08-03 | Pending | — | ||
| FND-0316 | Container image running as root in build pipeline3 of 11 images in the release pipeline declare no USER directive | Internal Audit | Moderate | ci-runner-pool | 2026-08-02 | Pending | — | ||
| FND-0311 | Unsupported OpenSSL version detectedOpenSSL 1.0.2u present on two bastion hosts; branch is end-of-life | Vulnerability Scan | Critical | bastion-prod-01 | 2026-06-14 | Converted | POAM-0142 | ||
| FND-0309 | MFA not enforced for privileged console accessBreak-glass accounts authenticate with a password only | 3PAO Assessment | Critical | identity-tenant | 2026-06-11 | Converted | POAM-0138 | ||
| FND-0305 | Anonymous read access on object storage bucketBucket policy permits unauthenticated LIST on a non-public bucket | Vulnerability Scan | High | nw-artifacts | 2026-06-02 | False Positive | — | ||
| FND-0298 | Quarterly access recertification not evidencedReviews performed but attestation records not retained | Customer Audit | Moderate | identity-tenant | 2026-05-21 | Converted | POAM-0163 | ||
| FND-0294 | Missing security headers on tenant web applicationCSP, HSTS and X-Frame-Options absent on three routes | Penetration Test | Low | app.northwind.gov | 2026-05-18 | Converted | POAM-0188 | ||
| FND-0290 | Duplicate of FND-0294 reported by second scannerMerged — tracked under the original finding | Vulnerability Scan | Low | app.northwind.gov | 2026-05-18 | Duplicate | — |