Issue 246: Critical flaw in API portal, securing GraphQL, building bulletproof APIs
Brief
This week, we have news of a critical flaw with a popular API portal. We also have guides on securing GraphQL APIs and building bulletproof APIs and news of a new deliberately vulnerable API application. We also have an article on why fraud detection and API security must converge. Dana Epp wraps things up with views on Bruno as a Postman alternative.
Vulnerability: Critical flaw in API portal allows SSRF attacks
This week, we have news of a critical vulnerability in the Perforce Akana Community Manager Developer and API portal. The flaw could enable malicious actors to perform server-side request forgery (SSRF) attacks.
Community Manager is a sophisticated tool that helps enterprises build an API portal to attract, manage, and support developers who create applications using their APIs. Organizations commonly employ it to develop and maintain developer portals for their APIs.
