UprootSecurityUprootSecurity

Curriculum · Phase 6 · Module 6.3

OWASP API Security Top 10 (2023)

The OWASP API Security Top 10 is the shared vocabulary auditors, pentesters, and engineers use to talk about API risk. This module walks all ten categories — from Broken Object Level Authorization (BOLA) to Unsafe Consumption of APIs — with a concrete example of each and the evidence that proves it is mitigated. You then find seeded flaws in a mock API specification and map each to its Top 10 category.

60 min

·

3 lessons

·

+40 pts

Article

The OWASP API Security Top 10 (2023), Category by Category

25 min

+10 pts

Video

Watch: BOLA + BFLA Exploited Live

10 min

+10 pts

Exercise

Find the OWASP API Top 10 Flaws in a Mock API

25 min

+20 pts

OWASP API Security Top 10 (2023) — UprootSecurity Bootcamp