curl --request GET \
--url https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id} \
--header 'X-API-KEY: <api-key>' \
--header 'X-CONNECTION-ID: <api-key>'import requests
url = "https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}"
headers = {
"X-API-KEY": "<api-key>",
"X-CONNECTION-ID": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'X-API-KEY': '<api-key>', 'X-CONNECTION-ID': '<api-key>'}
};
fetch('https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-KEY: <api-key>",
"X-CONNECTION-ID: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("X-CONNECTION-ID", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}")
.header("X-API-KEY", "<api-key>")
.header("X-CONNECTION-ID", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-KEY"] = '<api-key>'
request["X-CONNECTION-ID"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"severity": "CRITICAL",
"state": "OPEN",
"type": "DEPENDENCY",
"vendor_attributes": {
"id": "<string>",
"severity": "<string>",
"state": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"data": {
"report_type": "SAST",
"scanner": {
"id": "<string>",
"name": "<string>",
"vendor": "<string>"
},
"vendor": "GITLAB"
},
"updated_at": "2023-11-07T05:31:56Z",
"url": "<string>",
"vulnerability_identifiers": [
{
"type": "CVE",
"value": "CVE-2021-34527"
}
]
},
"analytic": {
"name": "<string>",
"type": "<string>",
"uid": "<string>",
"url": "<string>"
},
"analytic_output": "<string>",
"description": "<string>",
"exploitable": true,
"first_seen": "2023-11-07T05:31:56Z",
"has_fix": true,
"last_seen": "2023-11-07T05:31:56Z",
"product": {
"name": "<string>",
"vendor_name": "<string>"
},
"reachability": "REACHABLE",
"remediation": "<string>",
"resource_related": [
{
"affected_code": {
"end_line_number": 123,
"file_path": "<string>",
"start_line_number": 123,
"url": "<string>"
},
"affected_image": "<string>",
"affected_os": "<string>",
"affected_package": {
"name": "<string>",
"package_manager": "<string>",
"reachability": "REACHABLE",
"version": "<string>"
},
"affected_platform": "<string>",
"port": 123,
"protocol": "<string>",
"service": "<string>"
}
],
"resources": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"state": "ACTIVE",
"type": "BRANCH",
"vendor": "<string>",
"vendor_attributes": {
"id": "<string>",
"data": {
"host_id": "<string>",
"vendor": "qualys",
"asset_id": "<string>",
"tracking_method": "<string>"
}
},
"cloud_metadata": {
"account_id": "<string>",
"account_name": "<string>",
"cloud_provider": "<string>",
"image_id": "<string>",
"instance_id": "<string>",
"instance_type": "<string>",
"region": "<string>",
"subnet_id": "<string>",
"vpc_id": "<string>"
},
"data": {
"hostnames": [
"<string>"
],
"image": "<string>"
},
"first_seen": "2023-11-07T05:31:56Z",
"groups": [
{
"name": "<string>",
"uid": "<string>"
}
],
"last_seen": "2023-11-07T05:31:56Z",
"tags": [
{
"key": "<string>",
"source": "wiz_vms",
"value": "<string>"
}
],
"url": "<string>"
}
],
"state_updated_at": "2023-11-07T05:31:56Z",
"ticket": {
"status": "<string>",
"uid": "<string>",
"url": "<string>"
},
"title": "<string>",
"vulnerabilities": [
{
"uid": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"cvss_scores": [
{
"score": 123,
"vector": "<string>",
"version": "<string>",
"severity": "<string>"
}
],
"description": "<string>",
"last_modified": "2023-11-07T05:31:56Z",
"published": "2023-11-07T05:31:56Z",
"references": [
{
"url": "<string>",
"source": "<string>",
"tags": [
"<string>"
]
}
],
"source_identifier": "<string>",
"status": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"weaknesses": [
"<string>"
]
}
]
}{
"code": "<string>",
"detail": [
{}
],
"message": "<string>",
"type": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}Get Vulnerability Finding by ID
Get a vulnerability finding by ID.
curl --request GET \
--url https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id} \
--header 'X-API-KEY: <api-key>' \
--header 'X-CONNECTION-ID: <api-key>'import requests
url = "https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}"
headers = {
"X-API-KEY": "<api-key>",
"X-CONNECTION-ID": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'X-API-KEY': '<api-key>', 'X-CONNECTION-ID': '<api-key>'}
};
fetch('https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-KEY: <api-key>",
"X-CONNECTION-ID: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("X-CONNECTION-ID", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}")
.header("X-API-KEY", "<api-key>")
.header("X-CONNECTION-ID", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.leen.dev/v2/vulnerability_findings/{vulnerability_finding_id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-KEY"] = '<api-key>'
request["X-CONNECTION-ID"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"severity": "CRITICAL",
"state": "OPEN",
"type": "DEPENDENCY",
"vendor_attributes": {
"id": "<string>",
"severity": "<string>",
"state": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"data": {
"report_type": "SAST",
"scanner": {
"id": "<string>",
"name": "<string>",
"vendor": "<string>"
},
"vendor": "GITLAB"
},
"updated_at": "2023-11-07T05:31:56Z",
"url": "<string>",
"vulnerability_identifiers": [
{
"type": "CVE",
"value": "CVE-2021-34527"
}
]
},
"analytic": {
"name": "<string>",
"type": "<string>",
"uid": "<string>",
"url": "<string>"
},
"analytic_output": "<string>",
"description": "<string>",
"exploitable": true,
"first_seen": "2023-11-07T05:31:56Z",
"has_fix": true,
"last_seen": "2023-11-07T05:31:56Z",
"product": {
"name": "<string>",
"vendor_name": "<string>"
},
"reachability": "REACHABLE",
"remediation": "<string>",
"resource_related": [
{
"affected_code": {
"end_line_number": 123,
"file_path": "<string>",
"start_line_number": 123,
"url": "<string>"
},
"affected_image": "<string>",
"affected_os": "<string>",
"affected_package": {
"name": "<string>",
"package_manager": "<string>",
"reachability": "REACHABLE",
"version": "<string>"
},
"affected_platform": "<string>",
"port": 123,
"protocol": "<string>",
"service": "<string>"
}
],
"resources": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"state": "ACTIVE",
"type": "BRANCH",
"vendor": "<string>",
"vendor_attributes": {
"id": "<string>",
"data": {
"host_id": "<string>",
"vendor": "qualys",
"asset_id": "<string>",
"tracking_method": "<string>"
}
},
"cloud_metadata": {
"account_id": "<string>",
"account_name": "<string>",
"cloud_provider": "<string>",
"image_id": "<string>",
"instance_id": "<string>",
"instance_type": "<string>",
"region": "<string>",
"subnet_id": "<string>",
"vpc_id": "<string>"
},
"data": {
"hostnames": [
"<string>"
],
"image": "<string>"
},
"first_seen": "2023-11-07T05:31:56Z",
"groups": [
{
"name": "<string>",
"uid": "<string>"
}
],
"last_seen": "2023-11-07T05:31:56Z",
"tags": [
{
"key": "<string>",
"source": "wiz_vms",
"value": "<string>"
}
],
"url": "<string>"
}
],
"state_updated_at": "2023-11-07T05:31:56Z",
"ticket": {
"status": "<string>",
"uid": "<string>",
"url": "<string>"
},
"title": "<string>",
"vulnerabilities": [
{
"uid": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"cvss_scores": [
{
"score": 123,
"vector": "<string>",
"version": "<string>",
"severity": "<string>"
}
],
"description": "<string>",
"last_modified": "2023-11-07T05:31:56Z",
"published": "2023-11-07T05:31:56Z",
"references": [
{
"url": "<string>",
"source": "<string>",
"tags": [
"<string>"
]
}
],
"source_identifier": "<string>",
"status": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"weaknesses": [
"<string>"
]
}
]
}{
"code": "<string>",
"detail": [
{}
],
"message": "<string>",
"type": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}Path Parameters
Response
Successful Response
Leen's UUID for the vulnerability finding
Severity of the vulnerability finding
CRITICAL, HIGH, MEDIUM, LOW, INFO, UNKNOWN State of the vulnerability finding
OPEN, CLOSED, REOPENED, IGNORED, DELETED, UNKNOWN Type of the vulnerability finding
DEPENDENCY, CODE, SECRET, CONTAINER, IAC, HOST, DOMAIN, UNKNOWN Vendor-specific attributes of the finding
Show child attributes
Show child attributes
Analytic of the vulnerability finding
Show child attributes
Show child attributes
Analytic output of the vulnerability finding
Description of the vulnerability finding
Whether the vendor marked this finding exploitable — typically that a known exploit exists for the vulnerability. Null when the vendor provides no such signal. Package reachability is reported separately on resource_related[].affected_package.reachability.
First seen of the vulnerability finding
Has fix of the vulnerability finding
Last seen of the vulnerability finding
Product of the vulnerability finding
Show child attributes
Show child attributes
Finding-level reachability rollup over the affected packages, most-reachable-wins (REACHABLE > POTENTIALLY_REACHABLE > UNKNOWN > UNREACHABLE). Null when no package carries a vendor signal; UNKNOWN means analysis ran but was inconclusive. Per-package detail remains on resource_related[].affected_package.reachability.
REACHABLE, POTENTIALLY_REACHABLE, UNREACHABLE, UNKNOWN Remediation of the vulnerability finding
Resource related of the vulnerability finding
Show child attributes
Show child attributes
List of resources associated with the finding
Show child attributes
Show child attributes
Last time the state was updated for the finding
Ticket of the vulnerability finding
Show child attributes
Show child attributes
Title of the vulnerability finding
List of CVE Knowledge Base entries associated with the finding
Show child attributes
Show child attributes