Field Suggestion
Description
Field Suggestion allows users to infer the entire schema. Example of errors: Error: Field "XYZ" is missing
.
Remediation
Avoid providing verbose error messages to users in production.
REST Specific
Asp_net
Ruby_on_rails
Next_js
Laravel
Express_js
Django
Symfony
Spring_boot
Flask
Nuxt
Fastapi
Configuration
Identifier:
information_disclosure/rest_field_suggestion
Examples
Ignore this check
checks:
information_disclosure/rest_field_suggestion:
skip: true
Score
- Escape Severity: LOW
Compliance
OWASP: API3:2023
pci: 5.2.6
Classification
- CWE: 200