No products in the cart.
< 1 min read
Security
High
N/A
SN-RESTAPI_DATAMOD_NO_AUTHOR
Defining a REST API Resource with a data modification verb (POST/DELETE/PATCH) without authorization restrictions via ACLs is a security risk, as it allows any user with login credentials to modify data in your instance.
Ensure that all REST API Resources which can modify data have authentication and authorization checks enabled.
10 min
There was a problem reporting this post.
Please confirm you want to block this member.
You will no longer be able to:
Please allow a few minutes for this process to complete.