OWASP API Security Top 10 - 2023 OWASPAPI-3: Broken Object Property Level Authorization (BOPLA)
Address API3:2023 Broken Object Property Level Authorization (BOPLA) per OWASP API Security Top 10 2023. BOPLA combines previous API3 Excessive Data Exposure and API6 Mass Assignment categories. BOPLA occurs when an API exposes more properties than the authenticated user is entitled to read or allows the user to modify properties they should not be able to modify. Mitigations include (a) implement explicit object-to-output schema mapping with allowlist of fields per role + use case, (b) avoid generic serialisation that exposes all object properties, (c) validate input + reject unexpected properties + use explicit input schema, (d) implement property-level access control where appropriate, (e) test for over-disclosure + over-permissive update patterns.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 46 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)