Skip to content

[๐Ÿซ In-Person] Access Control Vulnerabilities in GraphQL with Bogdan Tiron ๐Ÿ”ž

Photo of Kevin Smith
Hosted By
Kevin S.
[๐Ÿซ In-Person] Access Control Vulnerabilities in GraphQL with Bogdan Tiron ๐Ÿ”ž

Details

This event will be a single talk on Examining Access Control Vulnerabilities in GraphQL - A Feeld Case Study with Bogdan Tiron

โš ๏ธ This will be an in-person event, the venue is Sheffield Tech Parks.

Agenda:

  • ๐Ÿ• Pizza/Drinks (18:15 - 18:30)
  • ๐Ÿ—ฃ Introduction (18:30)
  • ๐Ÿ‘‰ Examining Access Control Vulnerabilities in GraphQL - A Feeld Case Study
    (18:35ish)
  • ๐Ÿป Social @ Pub (after the talk)

๐Ÿ‘‰ Examining Access Control Vulnerabilities in GraphQL ๐Ÿ”ž
This talk explores the importance of implementing robust access controls in GraphQL and REST APIs and the severe consequences when these controls are not properly enforced. GraphQL, a flexible data query language, allows clients to request exactly the data they need, but without proper access control mechanisms, sensitive data can be easily exposed. Using the Feeld dating app as a case study, we will dive into a critical security review of how the lack of access controls in GraphQL and REST endpoints led to the exposure of usersโ€™ personal data, including sensitive photos, videos and private messages. This session will highlight common access control vulnerabilities in GraphQL and REST implementations , real-world examples of security lapses, their impact and remediation.

Photo of dotnetsheff group
dotnetsheff
See more events
Sheffield Technology Parks
Arundel Street ยท Sheffield
Google map of the user's next upcoming event's location
FREE