Authorization at the Object Level: Testing for BOLA Before Someone Else Does
Authorization at the Object Level: Testing for BOLA Before Someone Else Does Broken object level authorization is consistently at the top of the OWASP API Security Top 10, and it is consistently missed by automated scanners. The reason is that it is not a code defect in the usual sense. The endpoint authenticates the caller correctly, returns a valid response, and the response contains data the caller should not have. Nothing is malformed. The request is simply for someone else's object.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in