
SKesarla280155 (Community Member) asked a question.
Veracode Dynamic scan return few CEW 352 flaws as Samesite is not mention as Strict or LAX . Our product have different iframe with different domain so we set Samesite as None and Mitigated as "Potential Flase Positive" for pages it reported , but next Dynamic scan it return more flaws with CEW 353 as samesite cookie more pages
We have hundreds of pages with samesite is none, is there any veracode setting or policy in product level to set the Mitigated at high level not look for samesite
Thanks
Sreedhar
.png)
Hi @SKesarla280155 (Community Member) ,
Mitigation proposals cannot currently be applied on a CWE level, you must either apply mitigation proposals to each individual flaw or you may consider, with your security team, changing the policy set for your application or the severity of this CWE in the policy set for this application.
Thank you,
Boy Baukema