Back in April we took an in-depth look at the proposed OWASP Top-10 API Security Risks list for 2023. This Release Candidate (RC) contained a few changes from the 4-year-old version, most notably:
Well, it appears the final version of the OWASP API Security Top-10 2023 has been released, although you’d be forgiven for not knowing yet as it’s not on the project page, which still points to the (now removed) RC repo page.
And surprise, there are several changes from the RC version:
At first blush, the final 2023 version seems to retain most of the changes in category naming, language and intent from the 2019 edition which we saw in the RC version. In fact, the changes do not appear to have a big impact:
However, there are a couple of areas which stand out:
So, stay tuned as we dig into the details of the final 2023 OWASP Top-10 API Security Risks list, and help you understand the impact on your API security program.
Your board wants AI. Your developers are building with it. Your budget committee is asking…
AI systems are no longer just isolated models responding to human prompts. In modern production…
Broken authorization is one of the most widely known API vulnerabilities. It features in the…
The shadow technology problem is getting worse. Over the past few years, organizations have scaled…
API security has been a growing concern for years. However, while it was always seen…
It’s an unusually cold winter morning in Houston, and Craig Riddell is settling into his…