QID 570036
QID 570036: Invalid Host Value
In swagger file there should be a value for host.Valid value for host is the domain name or IP address of the server that serves the API. Values that are valid will have IP or domain with non-default port. The protocol or paths should not be present as part of the value. Value should not be empty. The value is used to generate documentation and code. Analysis of swagger shows that the host value is not valid.
Host value is not mandatory so there is no error just information disclosure. Given the invalid host value the generated documentation or code could have invalid values.
Solution
Review the host value and ensure it is a valid domain or IP address with out mention of protocol.
Vendor References
CVEs related to QID 570036
Software Advisories
| Advisory ID | Software | Component | Link |
|---|