API Security Weekly: Issue #14

This week there were a lot of reports of vulnerable APIs: from flight reservations systems to trading sites and even hot tubs. We also look into best practices for handling special characters in JSON and protecting APIs for mobile applications.

Vulnerabilities

Noam Rotem found a dangerous combination of vulnerabilities in APIs of Amadeus flight booking system and El Al airline: