QID 570060
QID 570060: Format UUID Not Enforced on Parameter ID
When IDs are defined on parameters the format should be defined as UUID. Random IDs are not compliant to swagger specification. Analysis of swagger file resulted in determining that parameter IDs are not enforced to be of UUID format
Analysis of swagger file results in an error. The swagger definition will not be spec compliant. Many code generators and automation around swagger definition might not work as expected since they might expect the ID to be of of UUID format.
Solution
Please review swagger definition and ensure any ID parameter is defined to be of type string with uuid format instead of type integer. For example:
openapi: "3.1.0" paths: /account/{id}/: get: description: "get" parameters: - name: id in: path schema: type: string format: uuid
Vendor References
CVEs related to QID 570060
Software Advisories
| Advisory ID | Software | Component | Link |
|---|