Refer to the exhibit. Which security vulnerability is most directly represented by the presence of the 'debug_info' field in the API response?
Exhibit
HTTP/1.1 200 OK
Content-Type: application/json
{
"status": "success",
"data": {
"user": "admin",
"role": "superuser",
"debug_info": "SELECT * FROM users WHERE id=101"
}
}Trap 1: SQL Injection
While the response contains information that facilitates SQL injection, the presence of the debug data itself is classified as Excessive Data Exposure. SQL injection is the exploitation of the input fields, whereas the exhibit shows the resulting information leak caused by poor API design.
Trap 2: Improper Asset Management
Improper Asset Management relates to the use of obsolete or unpatched API versions. The exhibit shows a data exposure issue rather than a versioning or lifecycle management problem. The issue is focused on what data is returned, not which version of the API is serving it.
Trap 3: Broken Object Level Authorization
Broken Object Level Authorization would manifest if the user was able to access data belonging to another user. The exhibit shows unnecessary information being returned for a successful request, which is an information disclosure issue, not an authorization failure regarding the object ownership.
- A
SQL Injection
Why it fails: While the response contains information that facilitates SQL injection, the presence of the debug data itself is classified as Excessive Data Exposure. SQL injection is the exploitation of the input fields, whereas the exhibit shows the resulting information leak caused by poor API design.
- B
Improper Asset Management
Why it fails: Improper Asset Management relates to the use of obsolete or unpatched API versions. The exhibit shows a data exposure issue rather than a versioning or lifecycle management problem. The issue is focused on what data is returned, not which version of the API is serving it.
- C
Excessive Data Exposure
Excessive Data Exposure occurs when an API returns more information than is necessary for the client to perform its function. Including internal debug data like raw SQL queries exposes backend implementation details to the client, providing attackers with valuable intelligence for future exploitation efforts.
- D
Broken Object Level Authorization
Why it fails: Broken Object Level Authorization would manifest if the user was able to access data belonging to another user. The exhibit shows unnecessary information being returned for a successful request, which is an information disclosure issue, not an authorization failure regarding the object ownership.