logo

Harnessing LLMs for Automating BOLA Detection

ID: a1385399-9747-5105-90d4-8104f24373c6

STIX ID: report--a1385399-9747-5105-90d4-8104f24373c6

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-08-12

Date Updated: 2026-04-28

Author: Ravid Mazon and Jay Chen

...
...

This Unit 42 report introduces BOLABuster, an LLM-driven methodology to automate detection of Broken Object Level Authorization (BOLA) vulnerabilities in API-based applications, outlining a five-stage workflow (identify potentially vulnerable endpoints, uncover endpoint dependencies, generate execution paths and test plans, create test scripts, execute and analyze) and reporting findings including CVE-2024-1313 (Grafana), CVE-2024-22278 (Harbor) and multiple Easy!Appointments CVEs; the paper discusses technical challenges, responsible disclosure, and implications of using AI for both defensive and offensive vulnerability research.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.