Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

object_refs in Report object #9831

Open
Matthew-Filigran opened this issue Feb 5, 2025 · 0 comments
Open

object_refs in Report object #9831

Matthew-Filigran opened this issue Feb 5, 2025 · 0 comments
Labels
bug use for describing something not working as expected needs triage use to identify issue needing triage from Filigran Product team

Comments

@Matthew-Filigran
Copy link

Description

Use case: data sharing by TAXII between OpenCTI (TAXII server) and 3rd party TAXII client.

The TAXII client throws an error when report object data does not include object_refs. The report used does not contain any object_refs (tested by exporting stix bundle).

According to the STIX 2.1 specification, the object_refs property in a Report object is required and must be a list of identifiers referencing other STIX objects. The specification does not explicitly state whether this list can be empty. However, since object_refs is mandatory, omitting it entirely would violate the specification. Therefore, a TAXII server should include the object_refs property in a Report object, even if it is an empty array ("object_refs": []).

This is preventing the ability to share reports to third parties.

@Matthew-Filigran Matthew-Filigran added bug use for describing something not working as expected needs triage use to identify issue needing triage from Filigran Product team labels Feb 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug use for describing something not working as expected needs triage use to identify issue needing triage from Filigran Product team
Projects
None yet
Development

No branches or pull requests

1 participant