QID 570077
QID 570077: String Parameter Definition in Schema is Lacking
Schemas of various components contain the definition of various parameters. The parameters can be of various types. Parameters definition of type string should have either a format, RegEx pattern, enum or const. Evaluation of swagger has determined that the string definition of a parameter is not complete.
Swagger is not compliant to specification and will result in an error. Having string definition that are restricted with limits will lead to lack of clarity to the API consumers and allow of attackers to abuse the API. Unexpected values can be sent over the API leading to overloading the server.
Solution
Please review swagger file and update your parameters of string type. In order to avoid unexpected values being sent or API abused, ensure that strings have either a format, RegEx pattern, enum, or `const. For example:
openapi: "3.0" info: version: "1.0" components: schemas: Foo: type: string format: email
Vendor References
CVEs related to QID 570077
Software Advisories
| Advisory ID | Software | Component | Link |
|---|