Undocumented HTTP status code

firetail:undefined-status-code

Type:

Observation

Rule Severity:

Low

Response has a status code that is not defined in the schema.

Systems that log and monitor HTTP status codes for performance or error tracking might not recognize undocumented status codes, resulting in incomplete or inaccurate monitoring data.

Remediation

Properly document all the response codes that an endpoint can return.

Example Attack Scenario

How to Identify with Example Scenario

How to Resolve with Example Scenario

How to Identify with Example Scenario

Find the text in bold to identify issues such as these in API specifications

How to Resolve with Example Scenario

Modify the text in bold to resolve issues such as these in API specifications
References:

More findings

All Findings