Preview of the Open Worldwide Application Security Project API Security Top 10 2023
As mentioned earlier in this chapter, the Open Worldwide Application Security Project API Security Top 10 is undergoing changes to reflect the API threat landscape in 2023. At the time of writing, this update was still in a release candidate stage, with an ongoing request for comment (RFC) in place via the Open Worldwide Application Security Project GitHub repository (https://github.com/OWASP/API-Security/tree/master/editions/2023/en).
Let us take a quick look at the currently proposed Top 10, shown in summary here:
# |
2019 |
2023 |
API1 |
Broken Object Level Authorization |
Broken Object Level Authorization |
API2 |
Broken User Authentication |
Broken Authentication... |