STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must limit the exposure of endpoints.

DISA Rule

SV-274557r1143590_rule

Vulnerability Number

V-274557

Group Title

SRG-APP-000141

Rule Version

SRG-APP-000141-API-000245

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to limit the endpoint against improper exposure.

Check Contents

Review the API documentation and configuration. If any endpoints (i.e., URLs or paths that handle client requests) are publicly accessible without a valid business or security justification, or if unnecessary endpoints are exposed, this is a finding.

Vulnerability Number

V-274557

Documentable

False

Rule Version

SRG-APP-000141-API-000245

Severity Override Guidance

Review the API documentation and configuration. If any endpoints (i.e., URLs or paths that handle client requests) are publicly accessible without a valid business or security justification, or if unnecessary endpoints are exposed, this is a finding.

Check Content Reference

M

Target Key

5703