OWASP / API-Security

OWASP API Security Project
https://owasp.org/www-project-api-security/
Other
2.07k stars 377 forks source link

Contradictory risk classification for "Unsafe Consumption of APIs" #123

Open mtausig opened 1 year ago

mtausig commented 1 year ago

The Exploitability of API10:2023 is graded with the highest rating of easy. At the same time, the corresponding textual explanation actually tells the opposite, that exploitation of this should be rather hard:

Exploiting this issue requires attackers to identify and potentially compromise other APIs/services the target API integrated with. Usually, this information is not publicly available or the integrated API/service is not easily exploitable.
kanakamamidiakhil commented 11 months ago

Hello, I'm interested in working on this issue. Could you please assign it to me? Thanks!