RDallfollo Portillo281817 (Community Member) asked a question.

Hi Folks,

How to fix issue Insertion of Sensitive Information Into Sent Data (CWE ID 201) when location is null 0% and in external libraries or internal modules (framework files) which does not have App Delegate?

We're running static analysis in iOS app and Veracode is reporting a weird issue: Insertion of Sensitive Information Into Sent Data (CWE ID 201). But the location is unknown (null 0%). We have already fixed the issue in the app layers based on the article: http://blogs.quovantis.com/best-practices-to-avoid-security-vulnerabilities-in-your-ios-app/ (Observation 5- Input Interception: Keyboard Extensions Allowed). However, after the fix when running new scans, at least one error per library (external, such as Firebase Crashlytics and internal ones - framework files) we are getting the same error.

 


  • Hi @RDallfollo Portillo281817 (Community Member)​ ,

     

    Veracode Static Analysis should not report locations of 'null'. I would recommend you contact our technical support team. Here's how you can log a case:

    1. Navigate to the upper right corner of any page in the Community, click on your user avatar.

    2. Select Contact Support from the drop-down menu.

    Please ensure that in your support case you provide a link to your results in the Veracode Platform with the relevant flaw ids.

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.