GlideRecord API usage in Scripted REST API Resource

Impact area

Security

Severity

High

Rule ID

SN-RESTAPI_GLIDERECORD

Impact

Scripted REST APIs should use the GlideRecordSecure API. This API ensures that access controls defined on the underlying data are applied for the requesting user.

Remediation

Ensure that all REST API Resources use GlideRecordSecure methods, instead of GlideRecord methods.

Time to fix

15 min




Last modified on Jun 9, 2020