Automated Black-Box Testing of Mass Assignment Vulnerabilities in RESTful APIs
Davide Corradini, Michele Pasqua, Mariano Ceccato
Abstract
Mass assignment is one of the most prominent vulnerabilities in RESTful APIs that originates from a misconfiguration in common web frameworks. This allows attackers to exploit naming convention and automatic binding to craft malicious requests that (massively) override data supposed to be read-only. In this paper, we adopt a black-box testing perspective to automatically detect mass assignment vulnerabilities in RESTful APIs. Indeed, execution scenarios are generated purely based on the OpenAPI specification, that lists the available operations and their message format. Clustering is used to group similar operations and reveal read-only fields, the latter are candidates for mass assignment. Then, test interaction sequences are automatically generated by instantiating abstract testing templates, with the aim of trying to use the found read-only fields to carry out a mass assignment attack. Test interactions are run, and their execution is assessed by a specific oracle, in order to reveal whether the vulnerability could be successfully exploited. The proposed novel approach has been implemented and evaluated on a set of case studies written in different programming languages. The evaluation highlights that the approach is quite effective in detecting seeded vulnerabilities, with a remarkably high accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 08a0248d-ee31-4b69-877f-ff41f23cc727Cited by top-tier papers3
- AGORA: Automated Generation of Test Oracles for REST APIsJuan C. Alonso, Sergio Segura, Antonio Ruiz-CortésISSTA 2023 · 15 citations
- A Multi-Agent Approach for REST API Testing with Semantic Graphs and LLM-Driven InputsMyeongsoo Kim, Tyler Stennett, Saurabh Sinha, Alessandro OrsoICSE 2025 · 4 citations
- Effective Directed Fuzzing with Hierarchical Scheduling for Web Vulnerability DetectionZihan Lin, Yuan Zhang, Jiarun Dai, Xinyou Huang et al.USENIX Security 2025
Builds on1
Related papers
- NAUTILUS: Automated RESTful API Vulnerability DetectionGelei Deng, Zhiyi Zhang, Yuekang Li, Yi Liu et al.USENIX Security 2023
- Effective REST APIs Testing with Error Message AnalysisLixin Xu, Huayao Wu, Zhenyu Pan, Tongtong Xu et al.ISSTA 2025 · 1 citation
- Combinatorial Testing of RESTful APIsHuayao Wu, Lixin Xu, Xintao Niu, Changhai NieICSE 2022 · 47 citations
- Morest: Model-based RESTful API Testing with Execution FeedbackYi Liu, Yuekang Li, Gelei Deng, Yang Liu et al.ICSE 2022 · 52 citations
- RESTGuardian: Automated Black-Box Fuzzing for RESTful API via Efficient Dependency Inference and Deep Vulnerability DetectionYifan Guo, Na Wang, Yunjia Wang, Zhenyu Chen et al.CCS 2026
