When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information
Hi @CSeaman145641 (Community Member) ,
Yes, the [ApiController] attribute introduced in .NET Core 2.1 does make manual checking of the ModelState.IsValid obsolete as documented by Microsoft: https://docs.microsoft.com/en-us/aspnet/core/web-api/index?view=aspnetcore-2.1 .
For now please mark these flaws as Potential False Positive in the Veracode Platform
or IDE plugin ( https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/~p4MSKOS8F8X8h0KwFTKoQ ) and have this reviewed by your security team.
Veracode Engineering is aware of this and working on updating the Veracode Static Analysis. To receive a notification when it has been updated you can find more on how to get notified about new release on our Help Centre: https://help.veracode.com/reader/kJC1iOtXp8N~rCtV8P9jhw/bvJJpfQ1tQEc8wpGdwjUhA .
Thank you,
Boy Baukema