SKesarla280155 (Community Member) asked a question.

Veracode Dynamic scan return few CEW 352 flaws as Samesite is not mention as Strict or LAX

Veracode Dynamic scan return few CEW 352 flaws as Samesite is not mention as Strict or LAX . Our product have different iframe with different domain so we set Samesite as None and Mitigated as "Potential Flase Positive" for pages it reported , but next Dynamic scan it return more flaws with CEW 353 as samesite cookie more pages

 

We have hundreds of pages with samesite is none, is there any veracode setting or policy in product level to set the Mitigated at high level not look for samesite

Thanks

Sreedhar

 


  • Hi @SKesarla280155 (Community Member)​ ,

     

    Mitigation proposals cannot currently be applied on a CWE level, you must either apply mitigation proposals to each individual flaw or you may consider, with your security team, changing the policy set for your application or the severity of this CWE in the policy set for this application.

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.