Collected research
a-deep-dive-into-openapi-security.pdf
A Deep Dive into OpenAPI Security
Treats an API's OpenAPI specification as a graph in a graph database, with endpoints, parameters and objects as nodes, so design flaws can be queried much as directory attack paths are. The queries surface sensitive data reachable through unprotected alternative paths, endpoints whose description contradicts their behaviour, and identifiers leaked by one endpoint that replay against another.
Record
- Document
- A Deep Dive into OpenAPI Security
- Researcher
- Andrei Agape
- Published by
- 0xpwn.wordpress.com
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Andrei Agape, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .