QID 570071
QID 570071: Operation is missing a `500` error response
OWASP API Security recommends defining schemas for all responses. 500 response code should have definition on all endpoints. Analysis of swagger file resulted in an observation that one or more of your operations do not have schemas for 500 response code
When user submits a request that results in 500 they do not have clarity from the API. The lack of schema definition for error code results in a warning.
Solution
Ensure the responses of all operations to include 500 response error codes. For example:
get:
summary: Provide details on the action of the get operation
tags: []
responses:
'200':
...
'400':
...
'429':
...
'500':
description: Internal Server Error
headers:
...
Vendor References
CVEs related to QID 570071
Software Advisories
| Advisory ID | Software | Component | Link |
|---|