Description
A global parameters definition applies to a request when referenced by an operation or path. An unused definition is not itself a security vulnerability, but stale definitions and incorrect references may need cleanup.
Potential impact
Readers may confuse the actual request parameters, and input changes may require reviewing unnecessary definitions.
Remediation
Connect needed parameters with the correct $ref. Check references from other documents before removing definitions that are no longer needed.
Examples
These POST examples correct the misspelled reference limitParame to the actual definition, limitParam.
Before
json
{
"swagger": "2.0",
"info": {
"title": "Simple API Overview",
"version": "1.0.0"
},
"paths": {
"/": {
"post": {
"operationId": "listVersionsv2",
"summary": "List API versions",
"responses": {
"200": {
"description": "200 response"
}
},
"parameters": [
{
"$ref": "#/parameters/limitParame"
}
]
}
}
},
"parameters": {
"limitParam": {
"name": "limit",
"in": "body",
"description": "max records to return",
"required": true,
"schema": {
"type": "string"
}
}
}
}
After
json
{
"swagger": "2.0",
"info": {
"title": "Simple API Overview",
"version": "1.0.0"
},
"paths": {
"/": {
"post": {
"operationId": "listVersionsv2",
"summary": "List API versions",
"responses": {
"200": {
"description": "200 response"
}
},
"parameters": [
{
"$ref": "#/parameters/limitParam"
}
]
}
}
},
"parameters": {
"limitParam": {
"name": "limit",
"in": "body",
"description": "max records to return",
"required": true,
"schema": {
"type": "string"
}
}
}
}