arXiv · 2405.01111
Mining REST APIs for Potential Mass Assignment Vulnerabilities
Abstract
REST APIs have a pivotal role in accessing protected resources. Despite the availability of security testing tools, mass assignment vulnerabilities are common in REST APIs, leading to unauthorized manipulation of sensitive data. We propose a lightweight approach to mine the REST API specifications and identify operations and attributes that are prone to mass assignment. We conducted a preliminary study on 100 APIs and found 25 prone to this vulnerability. We confirmed nine real vulnerable operations in six APIs.
Explore related subjects
Keep this discovery
Arash Mazidi, Davide Corradini, Mohammad Ghafari. 2024-05-02. Mining REST APIs for Potential Mass Assignment Vulnerabilities. https://doi.org/10.1145/3661167.3661204
Cite the original work for its findings. Save a collection to share your selection of sources.