OWASP / OWASP/crAPI

Add Security Misconfiguration vulnerabilities in crAPI

Open
#122 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement hacktoberfest
Dominant language
Java
Stars
1.6k
Forks
645
Avg merge
37m
Merged PRs (30d)
1

Description

Is your feature request related to a problem? Please describe.
We should be able to demo security misconfiguration vulnerabilities with crAPI. Security misconfiguration falls under API7:2019 Security Misconfiguration.

Describe the solution you'd like
There are CWEs which fall under security misconfigs:

We want to add capability in crAPI to be able to demo all three of them.

Describe alternatives if any you've considered
NA

Additional context
NA

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by reading the linked OWASP API7:2019 and CWE references, then inspect crAPI's existing vulnerability demos to define coverage for CWE-2, CWE-16, and CWE-388; done means all three security misconfiguration categories can be demonstrated in crAPI.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.