Description
In OpenAPI 2.0, http in the global schemes includes plaintext HTTP among the API's default transport protocols. Clients following the document may use that protocol.
Potential impact
Requests and responses sent over HTTP can be exposed or modified in transit.
Remediation
Remove http from global schemes and use https. Check operation overrides and configure HTTPS on the actual servers and gateways. Editing the specification alone does not disable HTTP access on the server.
Examples
These excerpts change the default transport protocol from HTTP to HTTPS.
Before
json
{
"swagger": "2.0",
"schemes": ["http"]
}
After
json
{
"swagger": "2.0",
"schemes": ["https"]
}