Description
In OpenAPI 3.0, global servers defines the API's default addresses. An HTTP address can lead clients to communicate in plaintext. If servers is omitted or empty, the default is the relative URL /, so check the protocol of the base URL used to resolve it.
Potential impact
If the actual connection uses HTTP, request credentials and response data can be exposed or modified in transit.
Remediation
Configure default server addresses to use HTTPS. Ensure relative URLs resolve against an HTTPS base URL and check path and operation server overrides. Configure HTTPS on the actual servers and gateways too.
Examples
These excerpts change the staging address to HTTPS and add an HTTPS production address.
Before
json
{
"openapi": "3.0.0",
"servers": [
{
"url": "https://development.gigantic-server.com/v1"
},
{
"url": "http://staging.gigantic-server.com/v1"
}
]
}
After
json
{
"openapi": "3.0.0",
"servers": [
{
"url": "https://development.gigantic-server.com/v1"
},
{
"url": "https://staging.gigantic-server.com/v1"
},
{
"url": "https://api.gigantic-server.com/v1"
}
]
}