Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Contradictory risk classification for "Unsafe Consumption of APIs" #123

Open
mtausig opened this issue Sep 25, 2023 · 1 comment
Open

Contradictory risk classification for "Unsafe Consumption of APIs" #123

mtausig opened this issue Sep 25, 2023 · 1 comment
Labels
2023 bug Something isn't working

Comments

@mtausig
Copy link

mtausig commented Sep 25, 2023

The Exploitability of API10:2023 is graded with the highest rating of easy.
At the same time, the corresponding textual explanation actually tells the opposite, that exploitation of this should be rather hard:

Exploiting this issue requires attackers to identify and potentially compromise other APIs/services the target API integrated with. Usually, this information is not publicly available or the integrated API/service is not easily exploitable.
@PauloASilva PauloASilva added bug Something isn't working 2023 labels Sep 27, 2023
@kanakamamidiakhil
Copy link

kanakamamidiakhil commented Dec 4, 2023

Hello, I'm interested in working on this issue. Could you please assign it to me? Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2023 bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants