RHeimerman135265 (Community Member) asked a question.

Are there any reasons why the the pipeline-scan.jar is not finding the flaws that the scan on the website is finding?

I recently set up on one of our pipeline to fail pr's if there are vulnerabilities. However, the pipeline scan is not finding the flaw that is found within scan that takes place on the "veracode website." I updated the jar to the latest version-- same behavior. I scanned the same artifact that the "veracode website" scans with the jar and that did not find the flaw either.

Not sure if it helps, but I'm scanning a jar file and it's a Cross-Site Request Forgery (CSRF) CWE ID 352 vulnerability.

 

I didn't know which forum to post this to. So if this is the incorrect place, I apologize.

 

Thanks


Topics (0)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.