• Hi @TChakraborty332682 (Community Member)​ ,

     

    Veracode Static Analysis reports flaws of CWE 501 when it can detect that data from the HTTP Request is being set to a session attribute. It is reported as this may mean you are mixing trusted and untrusted data or data with different trust levels.

     

    Unfortunately, there is no known cleansing method that we are able to recognize for this so the only way to get Veracode Static Analysis to automatically close these flaws is to hardcode the data or something other than the session.

     

    If you are unable to hardcode the data or use a different facility to store untrusted data we recommend applying strict input validation and documenting this control by proposing a mitigation. You can read more about how to propose a mitigation here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/~p4MSKOS8F8X8h0KwFTKoQ .

    After proposing a mitigation you must contact a member of your organizations security team. They will be able to review and approve mitigations.

     

    Please let me know if you have any remaining questions or concerns.

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.