vulnerability in the REST API