KPareek128104 (Community Member) asked a question.

Hi All,

Veracode identified XSS vulnerabilities in .net framework ( not on our code). Its in system_web_http_webhost_dll.System.Web.Http.WebHost.HttpControllerHandler..
Should I take it as fase positive or there is a way to mitigate.

  • Justin Yao (Veracode, Inc.)

    Great question, this may be the result of scan configuration & packaging. The recommendation is to make sure those modules are not included into the uploaded package. The Veracode Analysis Engine is already built with the .NET environments so those DLLs do not need to be individually included into the upload. For more discussion and clarity, I recommend scheduling a consultation call, and speak to an Application Security Consultant.

     

    Scheduling a Consultation

    https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/7YQTCDJKFEQzL3gL_N90hQ

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.