MHao145820 (Community Member) asked a question.

Flaw from com.veracode.virtualcontroller.VcHttpServletRequest?

hi there,

In my Veracode report, there is a line reporting as blow:

Start > 1

com.veracode.virtualcontroller.VcHttpServletRequest getParameterNames 236. What does this mean? I couldn't find the class VcHttpServletRequest.

 

Thanks,

Mike


  • Hi @MHao145820 (Community Member)​ ,

     

    During it's analysis Veracode Static Analysis may inject special artificial "VC..." classes to model data from annotations or frameworks. The "VcHttpServletRequest" class specifically models data from the HTTP request, for example from use of a @RequestMapping annotation from the Spring Framework.

     

    This is an artefact of our analysis and not part of your application and I'm sorry to see that this is part of your results please Contact Support (by clicking on your avatar in the top right corner of the Veracode Community) with the details for this scan (Veracode Platform URL to scan and flaw identifier) so we can relay this to Veracode Engineering for improvements.

     

    If you are unable to discern why a specific flaw was reported or how to fix it please consider scheduling a consultation with me or one of my colleagues to go through the flaw in detail. You can find more information on how to do this here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/7YQTCDJKFEQzL3gL_N90hQ .

     

    Thank you,

    Boy Baukema

    Expand Post
    Selected as Best
  • Hi @MHao145820 (Community Member)​ ,

     

    During it's analysis Veracode Static Analysis may inject special artificial "VC..." classes to model data from annotations or frameworks. The "VcHttpServletRequest" class specifically models data from the HTTP request, for example from use of a @RequestMapping annotation from the Spring Framework.

     

    This is an artefact of our analysis and not part of your application and I'm sorry to see that this is part of your results please Contact Support (by clicking on your avatar in the top right corner of the Veracode Community) with the details for this scan (Veracode Platform URL to scan and flaw identifier) so we can relay this to Veracode Engineering for improvements.

     

    If you are unable to discern why a specific flaw was reported or how to fix it please consider scheduling a consultation with me or one of my colleagues to go through the flaw in detail. You can find more information on how to do this here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/7YQTCDJKFEQzL3gL_N90hQ .

     

    Thank you,

    Boy Baukema

    Expand Post
    Selected as Best

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.