Skip to content

MASVS V4 and MSTG-AUTH-12 #624

Answered by cpholguera
naruoga asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @NAROUGA, thanks for reaching out. I can tell you that you're not missing anything. Unfortunately we don't have a test case in the MSTG for that requirement yet. We have an issue for it:

OWASP/owasp-mastg#1489

There's actually less that you can test on the app side besides ensuring that no authorization is being enforced within it. Similar to many other MASVS-AUTH requirements, this one is better tested directly on the remote endpoint.

Here's the OWASP WSTG that you might find what you need to test this kind of requirements:

https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/README

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by naruoga
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants