Skip to content

Commit 4104642

Browse files
committed
Added ASVS V13.2.3.yaml
1 parent 7da3f8d commit 4104642

File tree

1 file changed

+44
-0
lines changed

1 file changed

+44
-0
lines changed

templates/13.2.3.yaml

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
id: ASVS-4-0-3-V13-2-3
2+
3+
info:
4+
name: ASVS 13.2.3 Check
5+
author: Masoud Abdaal
6+
severity: medium
7+
classification:
8+
cwe-id: CWE-352
9+
reference:
10+
- https://github.com/OWASP/ASVS/blob/master/4.0/en/0x21-V13-API.md#v132-restful-web-service
11+
tags: asvs,13.2.3
12+
description: |
13+
Verify that RESTful web services that utilize cookies are protected from Cross-Site Request Forgery via the use of at least one or more of the following: double submit cookie pattern, CSRF nonces, or Origin request header checks
14+
15+
requests:
16+
- method: GET
17+
headers:
18+
Referer: "localhost"
19+
path:
20+
- "{{BaseURL}}"
21+
matchers:
22+
- type: status
23+
status:
24+
- 200
25+
26+
- method: GET
27+
headers:
28+
Referer: "127.0.0.1"
29+
path:
30+
- "{{BaseURL}}"
31+
matchers:
32+
- type: status
33+
status:
34+
- 200
35+
36+
- method: GET
37+
headers:
38+
Referer: "https://owasp.org"
39+
path:
40+
- "{{BaseURL}}"
41+
matchers:
42+
- type: status
43+
status:
44+
- 200

0 commit comments

Comments
 (0)