NM257998 (Community Member) asked a question.

Mitigating CWE-117 and code line number changes and the case reopens

The issue is mainly with CWE-117. Even if we use a cleansing function and that that with Veracode Attribute CRLFCleanser, the issue is open and it has to go through a mitigation process, security reviews and accepts the mitigation proposal - all good. As part of another change, the Controller code line changes, the same mitigated issue gets re opened - looks like it stores the line number for reference.

The best way is to have the scan engine detect the code and identify the issue is fixed.

 

  • Can Veracode suggest a clean cleansing function which satisfies the scan engine?

 

  • Is there a way to avoid this reopening of the issue just for the line change?

 

This is very painful during a very fast paced development. After the security reviews and approves the mitigation, we need to do again before the next deployment.

 


EGertis462759 likes this.
  • You can find our supported cleansing functions for Veracode Static Analysis at: https://help.veracode.com/r/review_cleansers . We would recommend using one of these cleansing functions consistently.

    Alternatively, if your log solution is not vulnerable to CRLF injection (for example, logging to JSON or using the ELK stack) you may wish to contact your security team to adjust the policy to remove and/or downgrade CWE 117 for your application or class of applications.

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.