GraphQL
V4.3.1
Verify that a query allowlist, depth limiting, amount limiting, or query cost analysis is used to prevent GraphQL or data layer expression Denial of Service (DoS) as a result of expensive, nested queries.
Required for Level 2 and 3
Related CAPEC™ Requirements
V4.3.2
Verify that GraphQL introspection queries are disabled in the production environment unless the GraphQL API is meant to be used by other parties.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 116, 169, 224, 54
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.