The current OWASP Top 10 Web application security risks as well as the OWASP API Top 10 security risks form the backbone of the web application and REST API interface security assessment services we provide for our clients.
- Injection
- Authentication errors
- Loss of confidentiality of sensitive data
- XML external entities (XXE)
- Access control errors
- Security-related misconfiguration
- Cross-site scripting (XSS)
- Insecure deserialization
- Use of components with known vulnerabilities
- Inadequate logging and monitoring
To further increase effectiveness, CODE Security recommends a combination of classic web application testing with a source code review of the web application and analysis of how your sites use REST APIs.