
RDallfollo Portillo281817 (Community Member) asked a question.
How to fix issue Insertion of Sensitive Information Into Sent Data (CWE ID 201) when location is null 0% and in external libraries or internal modules (framework files) which does not have App Delegate?
We're running static analysis in iOS app and Veracode is reporting a weird issue: Insertion of Sensitive Information Into Sent Data (CWE ID 201). But the location is unknown (null 0%). We have already fixed the issue in the app layers based on the article: http://blogs.quovantis.com/best-practices-to-avoid-security-vulnerabilities-in-your-ios-app/ (Observation 5- Input Interception: Keyboard Extensions Allowed). However, after the fix when running new scans, at least one error per library (external, such as Firebase Crashlytics and internal ones - framework files) we are getting the same error.
.png)
Hi @RDallfollo Portillo281817 (Community Member) ,
Veracode Static Analysis should not report locations of 'null'. I would recommend you contact our technical support team. Here's how you can log a case:
1. Navigate to the upper right corner of any page in the Community, click on your user avatar.
2. Select Contact Support from the drop-down menu.
Please ensure that in your support case you provide a link to your results in the Veracode Platform with the relevant flaw ids.
Thank you,
Boy Baukema
Hi @Boy, Security Consultant (Veracode) ,
I have contacted Support for help on this matter, but still waiting their feedback. Let's see how it goes.
Thanks a lot!