VentureBeat December 10, 2021
Nearly two-thirds of organizations lack at least a basic API security strategy, according to the latest report by Salt Security. This gap in protection is particularly worrisome as cyberattacks targeting APIs are on the rise alongside the adoption of relatively new technologies like GraphQL. GraphQL’s adoption has doubled from 2020 to 2021 and continues to accelerate. However, security awareness around GraphQL is still relatively low. Several aspects of GraphQL API structure can create security risks that can be difficult to assess.
Salt Labs, the research division of Salt Security, identified a novel GraphQL API authorization vulnerability that can arise in nested API queries. Salt Labs identified this vulnerability within a large business-to-business financial technology (fintech) platform, which offers financial services...