When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information
Hi @RPOLANI831351 (Community Member),
Thanks for your question. org.owasp.encoder.Encode.forJava is a supported cleanser (https://help.veracode.com/reader/4EKhlLSMHm5jC8P8j3XccQ/IiF_rOE79ANbwnZwreSPGA) for CWE-93 and when used correctly should result in the flaw not being presented. Could it be that there is another parameter or some other component of that which has not passed through this cleanser? I would recommend reading the Attack Vector and Description details for the flaw in the Triage Flaws page to get an idea where exactly the flaw was found.
I recommend scheduling a consultation with a Veracode Application Security Consultant if you would like to discuss this specific flaw. You can find details on how to schedule a consultation here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/7YQTCDJKFEQzL3gL_N90hQ.
I hope that was useful to you.
Many thanks,
Anthony Fielding